5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the file /addproduct.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-11612
Source
VulDB
Published
Oct 11, 2025 at 19:02
Affected Product
Vendor
code-projects
Product
Simple Food Ordering System
Version
1.0
Affected Versions
code-projects Simple Food Ordering System 1.0