CVE-2026-19917

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

Credits

SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User)

References