cbcvebase.
CVE-2025-12302
published 2025-10-27

CVE-2025-12302: A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php…

low2.1CVSS 4.0
AVNACLATNPRNUIPVCNVILVANSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

Affected

2 ranges
VendorProductVersion rangeFixed in
code-projectssimple_food_ordering_system
fabiansimple_food_ordering_system