5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-13290
Source
VulDB
Published
Nov 17, 2025 at 16:32
Modified
Nov 17, 2025 at 16:59
Affected Product
Vendor
code-projects
Product
Simple Food Ordering System
Version
1.0
Affected Versions
code-projects Simple Food Ordering System 1.0