SQL Injection in AdithyaYelloju Restaurant-Management-System
The Restaurant-Management-System contains a remote SQL injection vulnerability in the admin/delete1.php script, allowing unauthenticated attackers to manipulate the ID parameter.
CVE search metadata
CVE search record: CVE-2026-103229. Severity: high. CVSS: 7.3. KEV: no. Product: Restaurant-Management-System. Brief: SQL Injection in AdithyaYelloju Restaurant-Management-System. Brief link: https://feed.craftedsignal.io/briefs/2026-09-restaurant-system-sqli/
The Restaurant-Management-System project, maintained by AdithyaYelloju, contains a critical SQL injection vulnerability identified as CVE-2026-103229. The flaw resides in the 'admin/delete1.php' file, specifically within the 'mysqli_query' function used to process user input. An unauthenticated, remote attacker can execute arbitrary SQL commands by manipulating the 'ID' argument passed to this script. The project follows a continuous delivery model with rolling releases, meaning no specific version identifiers exist to distinguish vulnerable from patched code; all implementations prior to the remediation commit are considered affected. The vulnerability has been publicly disclosed and PoC exploit code is available, heightening the risk of exploitation. Defenders should inspect web server access logs for anomalous SQL syntax within requests targeting the 'admin/delete1.php' endpoint.
Impact
Successful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the backend database. This may lead to unauthorized data exfiltration, database structure modification, or potential credential theft from the application database. Given the nature of the application, this could result in the exposure of sensitive restaurant operations, staff data, or customer information.
Recommendation
- Monitor web server logs for HTTP requests to 'admin/delete1.php' that contain SQL control characters or keywords (e.g., UNION, SELECT, SLEEP) in the 'ID' parameter.
- Implement a Web Application Firewall (WAF) rule to block or sanitize requests containing common SQL injection payloads targeting this specific file path.
- Review the project repository for commits addressing this issue and prioritize migrating to a version incorporating the fix, as the application does not utilize versioned releases.
- Restrict network access to the 'admin/' directory of the application to trusted administrative IP ranges only.
Immediate actions
Implement WAF blocking for the identified URL path and parameter pattern.
Mitigations
Restrict access to the /admin/ directory to internal IP ranges.
CVE-2026-103229
Detection coverage 1
Detects CVE-2026-103229 Exploitation - SQL Injection in admin/delete1.php
highDetects potential SQL injection attempts against the Restaurant-Management-System by searching for common SQL keywords or special characters in the ID parameter of admin/delete1.php requests.
Detection queries are available on the platform. Get full rules →