5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/deleteitem.php. Performing manipulation of the argument itemID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-12314
Source
VulDB
Published
Oct 27, 2025 at 20:02
Modified
Oct 27, 2025 at 20:21
Affected Product
Vendor
code-projects
Product
Food Ordering System
Version
1.0
Affected Versions
code-projects Food Ordering System 1.0