Vulnerability Description
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://code-projects.org/
- https://gist.github.com/HxH404/f7f1502ffc9f2aacc936a6e8f290b6a5
- https://vuldb.com/submit/776186
- https://vuldb.com/vuln/354189
- https://vuldb.com/vuln/354189/cti
FAQ
What is CVE-2026-5157?
CVE-2026-5157 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the arg...
How severe is CVE-2026-5157?
CVE-2026-5157 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5157?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.