{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/sililawijesinghe/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-79804"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Food Ordering System"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","cve-2026-79804"],"_cs_type":"threat","_cs_vendors":["SililaWijesinghe"],"content_html":"\u003cp\u003eA SQL injection vulnerability exists in the SililaWijesinghe Food Ordering System, specifically affecting the search_box argument within the search.php file. This vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. Publicly available exploit code exists, increasing the risk of active exploitation. The product follows a rolling release model, meaning no specific version numbers are provided, and the vulnerability persists in versions up to commit ba314e897e3365600461e5ea59432e39ceaa0fa5. The vendor has not provided a patch or a response to disclosure attempts, necessitating manual monitoring and defensive controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized database access, which could lead to data exfiltration, modification of application content, or administrative compromise of the underlying database. Given the application's nature, sensitive customer or order information may be exposed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web application logs for suspicious characters in the search_box parameter, such as single quotes, double dashes, OR/AND logical operators, and UNION SELECT statements.\u003c/li\u003e\n\u003cli\u003eApply strict input validation or use parameterized queries for the search_box parameter in search.php if internal code modifications are possible.\u003c/li\u003e\n\u003cli\u003eIf the application cannot be patched, place the web server behind a Web Application Firewall (WAF) configured to block SQL injection payloads targeting the /search.php endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict database account permissions used by the application to the absolute minimum required for operation to limit the impact of potential injection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T22:49:36Z","date_published":"2026-08-25T22:49:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-79804/","summary":"A SQL injection vulnerability in the search_box argument of search.php allows remote attackers to perform unauthorized database operations on the SililaWijesinghe Food Ordering System.","title":"SQL Injection Vulnerability in SililaWijesinghe Food Ordering System","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-79804/"}],"language":"en","title":"CraftedSignal Threat Feed - SililaWijesinghe","version":"https://jsonfeed.org/version/1.1"}