CVE-2026-5811
MEDIUMSourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic error
Title source: cnaDescription
A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The attack may be performed from remote. The exploit is publicly available and might be used.
Scores
CVSS v3
5.4
EPSS
0.0004
EPSS Percentile
13.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Details
CWE
CWE-840
Status
published
Products (1)
SourceCodester/Online Food Ordering System
1.0
Published
Apr 08, 2026
Tracked Since
Apr 09, 2026