PT-2026-35283 · Codepanda Source · Canteen Management System

N0Name

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7072

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in CodePanda Source canteen management system 1.0. Affected by this issue is some unknown functionality of the file /api/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7072

Affected Products

Canteen Management System