PT-2026-81879 · Unknown · Sililawijesinghe Food Ordering System

·

CVE-2026-79804

·

Published

2026-08-25

·

Updated

2026-08-26

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SililaWijesinghe Food Ordering System versions up to ba314e897e3365600461e5ea59432e39ceaa0fa5
Description An issue exists in the /search.php endpoint where manipulation of the search box variable allows for SQL injection. This allows remote attackers to execute unauthorized database queries.
Recommendations Update SililaWijesinghe Food Ordering System to a version later than ba314e897e3365600461e5ea59432e39ceaa0fa5. As a temporary mitigation, restrict access to the /search.php endpoint.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79804

Affected Products

Sililawijesinghe Food Ordering System