CVE-2026-78198

7.3

SourceCodester · Simple Online Food Ordering System

SourceCodester Simple Online Food Ordering System version 1.0 contains a SQL injection vulnerability that allows unauthenticated remote code execution or data extraction.

Executive summary

An unauthenticated SQL injection vulnerability in SourceCodester Simple Online Food Ordering System version 1.0 poses a severe risk to system and data security.

Vulnerability

This is a SQL injection vulnerability (CWE-89) that allows an unauthenticated attacker to inject malicious SQL commands into the application database.

Business impact

An attacker successfully exploiting this flaw can bypass standard security controls to read, modify, or delete sensitive information from the database. A CVSS score of 7.3 underscores the high risk of this vulnerability, which could lead to significant financial loss and loss of customer trust.

Remediation

Immediate Action: There is no official patch at this time, so administrators should restrict network access to the application immediately.

Proactive Monitoring: Regularly audit application logs for signs of unauthorized database manipulation or unexpected error messages.

Compensating Controls: Utilize a Web Application Firewall (WAF) to detect and block SQL injection payloads targeting the application.

Exploitation status

Public Exploit Available: No confirmed public exploit exists in the provided data.

Analyst recommendation

The vulnerability represents a significant security gap that requires immediate attention. Given the lack of a vendor-provided patch, organizations must rely on network-level defenses and WAF rules to prevent exploitation until the vendor issues a remediation update.

More SourceCodester CVEs