{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-food-ordering-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sourcecodester:online_food_ordering_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90854"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Food Ordering System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","cve"],"_cs_type":"advisory","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability has been identified in the SourceCodester Online Food Ordering System version 1.0. The vulnerability exists within the /web/category-foods.php file, where the ID argument is insufficiently sanitized before being used in database queries. An attacker can leverage this flaw to perform remote SQL injection, potentially leading to unauthorized data exfiltration, modification, or deletion within the underlying database. The vulnerability has been confirmed with a CVSS v3.1 base score of 7.3, and public exploit code is available, increasing the risk of exploitation by opportunistic threat actors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to compromise the integrity and confidentiality of the application database. In an Online Food Ordering System, this could lead to the exposure of customer personal information, order history, and potentially administrative credentials, posing a significant risk to the privacy of users and the operational security of the host organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor web server logs for suspicious patterns in URI queries associated with the affected file to identify and block exploitation attempts.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for the /web/category-foods.php endpoint to detect common SQL injection syntax in the ID parameter.\u003c/li\u003e\n\u003cli\u003ePatch or isolate instances of Online Food Ordering System 1.0, as no official vendor patch is currently available; consider moving the application behind a Web Application Firewall (WAF) with SQL injection protection rules enabled.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T03:38:29Z","date_published":"2026-09-15T03:38:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90854/","summary":"Online Food Ordering System 1.0 contains a SQL injection vulnerability in /web/category-foods.php that allows remote, unauthenticated attackers to execute arbitrary database queries via the ID argument.","title":"SQL Injection Vulnerability in Online Food Ordering System","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90854/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Food Ordering System (1.0)","version":"https://jsonfeed.org/version/1.1"}