<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Online Food Ordering System (1.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/online-food-ordering-system-1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 03:38:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/online-food-ordering-system-1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in Online Food Ordering System</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90854/</link><pubDate>Tue, 15 Sep 2026 03:38:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90854/</guid><description>Online Food Ordering System 1.0 contains a SQL injection vulnerability in /web/category-foods.php that allows remote, unauthenticated attackers to execute arbitrary database queries via the ID argument.</description><content:encoded><![CDATA[<p>A critical SQL injection vulnerability has been identified in the SourceCodester Online Food Ordering System version 1.0. The vulnerability exists within the /web/category-foods.php file, where the ID argument is insufficiently sanitized before being used in database queries. An attacker can leverage this flaw to perform remote SQL injection, potentially leading to unauthorized data exfiltration, modification, or deletion within the underlying database. The vulnerability has been confirmed with a CVSS v3.1 base score of 7.3, and public exploit code is available, increasing the risk of exploitation by opportunistic threat actors.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to compromise the integrity and confidentiality of the application database. In an Online Food Ordering System, this could lead to the exposure of customer personal information, order history, and potentially administrative credentials, posing a significant risk to the privacy of users and the operational security of the host organization.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor web server logs for suspicious patterns in URI queries associated with the affected file to identify and block exploitation attempts.</p>
<ul>
<li>Implement monitoring for the /web/category-foods.php endpoint to detect common SQL injection syntax in the ID parameter.</li>
<li>Patch or isolate instances of Online Food Ordering System 1.0, as no official vendor patch is currently available; consider moving the application behind a Web Application Firewall (WAF) with SQL injection protection rules enabled.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>sql-injection</category><category>cve</category></item></channel></rss>