PT-2026-25911 · Code Projects · Simple Food Ordering System

Xuyue

·

Published

2026-03-17

·

Updated

2026-03-17

·

CVE-2026-4319

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/add-item.php. Such manipulation of the argument price leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4319

Affected Products

Simple Food Ordering System