{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/adithyayelloju/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adithyayelloju:restaurant_management_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-103229"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Restaurant-Management-System"],"_cs_severities":["high"],"_cs_tags":["web-application","sqli","vulnerability"],"_cs_type":"advisory","_cs_vendors":["AdithyaYelloju"],"content_html":"\u003cp\u003eThe Restaurant-Management-System project, maintained by AdithyaYelloju, contains a critical SQL injection vulnerability identified as CVE-2026-103229. The flaw resides in the 'admin/delete1.php' file, specifically within the 'mysqli_query' function used to process user input. An unauthenticated, remote attacker can execute arbitrary SQL commands by manipulating the 'ID' argument passed to this script. The project follows a continuous delivery model with rolling releases, meaning no specific version identifiers exist to distinguish vulnerable from patched code; all implementations prior to the remediation commit are considered affected. The vulnerability has been publicly disclosed and PoC exploit code is available, heightening the risk of exploitation. Defenders should inspect web server access logs for anomalous SQL syntax within requests targeting the 'admin/delete1.php' endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the backend database. This may lead to unauthorized data exfiltration, database structure modification, or potential credential theft from the application database. Given the nature of the application, this could result in the exposure of sensitive restaurant operations, staff data, or customer information.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests to 'admin/delete1.php' that contain SQL control characters or keywords (e.g., UNION, SELECT, SLEEP) in the 'ID' parameter.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block or sanitize requests containing common SQL injection payloads targeting this specific file path.\u003c/li\u003e\n\u003cli\u003eReview the project repository for commits addressing this issue and prioritize migrating to a version incorporating the fix, as the application does not utilize versioned releases.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the 'admin/' directory of the application to trusted administrative IP ranges only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T16:35:47Z","date_published":"2026-09-30T16:35:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-restaurant-system-sqli/","summary":"The Restaurant-Management-System contains a remote SQL injection vulnerability in the admin/delete1.php script, allowing unauthenticated attackers to manipulate the ID parameter.","title":"SQL Injection in AdithyaYelloju Restaurant-Management-System","url":"https://feed.craftedsignal.io/briefs/2026-09-restaurant-system-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - AdithyaYelloju","version":"https://jsonfeed.org/version/1.1"}