What is CVE-2026-76048?
A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System 1.0, specifically in the `/admin/ajax.php?action=login` file. A remote attacker can manipulate the Username argument to gain unauthorized database access. Proper input validation and parameterized queries are strongly recommended to mitigate this flaw.
Azərbaycanca: SourceCodester Simple Online Food Ordering System 1.0 sisteminin `/admin/ajax.php?action=login` faylında SQL injection zəifliyi aşkarlanıb. Uzaqdan hücumçu Username arqumentini manipulyasiya edərək verilənlər bazasına yetkisiz giriş əldə edə bilər. Bu təhlükəsizlik boşluğundan qorunmaq üçün daxil olan məlumatların ciddi validasiyası və parametrləşdirilmiş sorğuların istifadəsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which file is associated with the SQL injection vulnerability in SourceCodester Simple Online Food Ordering System 1.0?
The vulnerability is identified in the `/admin/ajax.php?action=login` file.
Which argument is manipulated in this SQL injection attack?
A remote attacker can manipulate the 'Username' argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.