Vulnerability Description
A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Carmelo | Simple Food Order System | 1.0 |
Related Weaknesses (CWE)
References
- https://code-projects.org/Product
- https://github.com/6Justdododo6/CVE/issues/15ExploitIssue TrackingMitigation
- https://vuldb.com/submit/779331VDB EntryThird Party Advisory
- https://vuldb.com/vuln/353902Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/353902/ctiVDB EntryPermissions Required
FAQ
What is CVE-2026-5017?
CVE-2026-5017 is a vulnerability with a CVSS score of 7.3 (HIGH). A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipu...
How severe is CVE-2026-5017?
CVE-2026-5017 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5017?
Check the references section above for vendor advisories and patch information. Affected products include: Carmelo Simple Food Order System.