PT-2026-31549 · Sourcecodester · Sourcecodester Online Food Ordering System
Fukun
·
Published
2026-04-08
·
Updated
2026-04-09
·
CVE-2026-5811
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Online Food Ordering System version 1.0
Description
A vulnerability exists in the function
save product of the file /Actions.php within the POST Parameter Handler component. Manipulation of the price argument can lead to business logic errors. The attack can be performed remotely, and an exploit is publicly available.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
/Actions.php file or disabling the save product function until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Online Food Ordering System