PT-2026-28732 · Unknown · Simple Food Ordering System

Xuyue

·

Published

2026-03-28

·

Updated

2026-03-29

·

CVE-2026-5018

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Food Order System version 1.0
Description A flaw exists in Simple Food Order System 1.0 related to the handling of parameters. Specifically, manipulating the Name argument can lead to SQL injection. This issue affects an unknown function within the register-router.php file of the Parameter Handler component and can be exploited remotely. The exploit code is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5018

Affected Products

Simple Food Ordering System