A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argument custom leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argument custom leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | SourceCodester Food Ordering System Parameter purchase.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-26T03:14:29.693Z
Reserved: 2026-03-25T14:30:21.273Z
Link: CVE-2026-4839
No data.
Status : Received
Published: 2026-03-26T04:17:15.053
Modified: 2026-03-26T04:17:15.053
Link: CVE-2026-4839
No data.
OpenCVE Enrichment
No data.