CVE-2026-78197
published 2026-08-24CVE-2026-78197: A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file…
PriorityP345high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.27%
18.4th percentile
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | simple_online_food_ordering_system | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SourceCodester Simple Online Food Ordering System 1.0 ajax.php?action=save_user Username sql injection
vuldb·2026-08-24
CVE-2026-78197 [CRITICAL] SourceCodester Simple Online Food Ordering System 1.0 ajax.php?action=save_user Username sql injection
A vulnerability marked as critical has been reported in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection.
This vulnerability appears as CVE-2026-78197. The attack may be initiated remotely. In addition, an exploit is available.
GHSA
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0.
ghsa_unreviewed·2026-08-24
CVE-2026-78197 [MEDIUM] CWE-74 A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0.
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-24
Published