CVE-2026-76998

Summary

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Affected Software

VendorProductVersion RangeStatus
SourceCodesterSimple Online Food Ordering System1.0affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

References