What is CVE-2026-76049?
This critical SQL injection vulnerability was found in the /admin/ajax.php file of SourceCodester Simple Online Food Ordering System 1.0. Improper sanitization of the 'ID' argument allows remote attackers to execute arbitrary SQL commands. It is recommended to use prepared statements and validate user inputs to mitigate the risk.
Azərbaycanca: Bu kritik SQL injection zəifliyi SourceCodester Simple Online Food Ordering System 1.0 versiyasının /admin/ajax.php faylında tapılıb. 'ID' arqumentinin düzgün yoxlanılmaması uzaqdan hücuma imkan verir. Təhlükəsizlik üçün istifadəçi girişlərini yoxlamaq və prepared statement-lərdən istifadə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which version of SourceCodester Simple Online Food Ordering System is affected by the CVE-2026-76049 SQL injection vulnerability?
This vulnerability was found in version 1.0 of SourceCodester Simple Online Food Ordering System.
What security measures are recommended to mitigate the CVE-2026-76049 vulnerability?
It is recommended to use prepared statements and validate user inputs to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.