What is CVE-2026-19917?
This SQL injection vulnerability exists in code-projects Online Food Order System 1.0. An attacker can remotely exploit the 'checkbox' parameter in the delete_food_items1.php file to execute unauthorized database queries. It is recommended to update the system or to implement input validation and parameterized queries.
Azərbaycanca: Bu SQL injection zəifliyi code-projects Online Food Order System 1.0-da tapılıb. Təcavüzkar delete_food_items1.php faylındakı 'checkbox' parametrini manipulyasiya edərək verilənlər bazasına icazəsiz sorğular göndərə bilər. Mümkün olduqca sistemi yeniləmək və ya təsirlənən fayldakı istifadəçi girişini filtrasiya etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: code-projects
FAQ2
Which version of code-projects Online Food Order System is affected by CVE-2026-19917?
This SQL injection vulnerability exists in code-projects Online Food Order System version 1.0.
Which file and parameter are targeted to exploit CVE-2026-19917?
An attacker can remotely exploit this vulnerability by manipulating the 'checkbox' parameter in the delete_food_items1.php file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.