PT-2026-28731 · Code Projects · Simple Food Ordering System

Xuyue

·

Published

2026-03-28

·

Updated

2026-03-29

·

CVE-2026-5017

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Simple Food Order System version 1.0
Description A security flaw exists in code-projects Simple Food Order System version 1.0. The issue resides in the Parameter Handler component, specifically within the file /all-tickets.php. Manipulation of the Status argument can lead to SQL injection. This attack can be initiated remotely. The exploit has been publicly released.
Recommendations Apply any available updates or patches for code-projects Simple Food Order System version 1.0. As a temporary workaround, restrict access to the /all-tickets.php file. Sanitize the Status parameter before using it in any database queries.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5017

Affected Products

Simple Food Ordering System