CVE-2026-4841 Details
Description
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
A critical SQL injection vulnerability has been identified in the Online Food Ordering System version 1.0 by Code-Projects. The issue resides in the Shopping Cart Module, specifically within the file form/cart.php. The vulnerability is triggered by manipulating the del parameter, which is passed directly to a SQL query without proper sanitization or parameterization. This flaw allows for time-based blind SQL injection, where an attacker can execute arbitrary SQL commands and observe the application's response time as a confirmation of the injection's success. The vulnerability can be exploited remotely, without any authentication or user interaction.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 26, 2026CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Not ApplicableVendor |
| https://gist.github.com/HxH404/ed090db972001ba535202fd4f5b6a0b5 | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.353147 | [email protected] | Content Wall |
| https://vuldb.com/?id.353147 | [email protected] | AdvisoryExploitTechnical Description |
| https://vuldb.com/?submit.776130 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| code-projects Online Food Ordering System | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |
Volerion