What is CVE-2026-76050?
A SQL injection vulnerability was discovered in SourceCodester Simple Online Food Ordering System 1.0, affecting the `/admin/ajax.php?action=delete_menu` file. The flaw allows remote exploitation via manipulation of the 'ID' argument, posing a database compromise risk. It is recommended to urgently sanitize user inputs or update the software.
Azərbaycanca: SourceCodester Simple Online Food Ordering System 1.0-da `/admin/ajax.php?action=delete_menu` faylında SQL injection zəifliyi aşkar edilib. Uzaqdan istismar mümkündür və 'ID' parametrinin manipulyasiyası nəticəsində məlumat bazasına müdaxilə riski yaranır. Təcili olaraq daxil olan məlumatları filtrləmək və ya proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
In which file of SourceCodester Simple Online Food Ordering System 1.0 is the SQL injection vulnerability exploited?
The vulnerability is located in the `/admin/ajax.php?action=delete_menu` file.
What urgent measures should be taken to mitigate this security flaw?
It is recommended to urgently sanitize user inputs or update the software.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.