๐Ÿ” CVE Alert

CVE-2026-103231

HIGH 7.3

AdithyaYelloju Restaurant-Management-System Order Cancellation cancel.php mysqli_query sql injection

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-89 CWE-74
Vendor adithyayelloju
Product restaurant-management-system
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for adithyayelloju restaurant-management-system

Be the first to know when new high vulnerabilities affecting adithyayelloju restaurant-management-system are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

AdithyaYelloju / Restaurant-Management-System
7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/411924 vuldb.com: https://vuldb.com/vuln/411924/cti vuldb.com: https://vuldb.com/cve/CVE-2026-103231 vuldb.com: https://vuldb.com/submit/955080 github.com: https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/7 github.com: https://github.com/AdithyaYelloju/Restaurant-Management-System/

Credits

๐Ÿ” 100001001X (VulDB User) VulDB CNA Team