CVE-2026-14622

HIGH

jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication

Title source: cna
STIX 2.1

Description

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry vdb-entry
VDB-376138 | jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
https://vuldb.com/vuln/376138
Signature, Permissions Required signature permissions-required
VDB-376138 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/376138/cti
Third Party Advisory third-party-advisory
CVE-2026-14622 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-14622
Third Party Advisory third-party-advisory
Submit #845099 | jairiidriss restaurant-website-php-mysql 1.0 jairiidriss Restaurant Website PHP MySQL 1.0 missing authenticat
https://vuldb.com/submit/845099

Scores

CVSS v3 7.3
EPSS 0.0041
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (1)
jairiidriss/restaurant-website-php-mysql 521428b5b612449df0cf4a5d15ee40cba67f3d35
Published Jul 04, 2026
Tracked Since Jul 04, 2026