CVE-2026-10694: fallo de gravedad media en SourceCodester Online Food Ordering System
SourceCodester Online Food Ordering System index.php include file inclusion
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 6.9epss 0.3%
probabilidad de explotación
0.3%top 79% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
SourceCodester · Online Food Ordering SystemPoCs públicas encontradas — 1
cve_referencegithub.com/Mikkoseven/cve/issues/4no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — SourceCodester Online Food Ordering System
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-0332HIGHSourceCodester Online Food Ordering System manage_user.php sql injectionEPSS 0.9%CVE-2023-0305MEDIUMSourceCodester Online Food Ordering System Login Module admin_class.php sql injectionEPSS 0.6%CVE-2023-0304MEDIUMSourceCodester Online Food Ordering System Signup Module admin_class.php sql injectionEPSS 0.6%CVE-2023-0303MEDIUMSourceCodester Online Food Ordering System view_prod.php sql injectionEPSS 0.6%CVE-2023-1432HIGHSourceCodester Online Food Ordering System POST Request access controlEPSS 0.6%CVE-2024-8604MEDIUMSourceCodester Online Food Ordering System Create an Account Page index.php cross site scriptingEPSS 0.6%