


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulati…
Published:
8 juli 2026 om 22:00:00
Alert date:
9 juli 2026 om 01:01:55
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities
A SQL injection vulnerability has been identified in code-projects Online Food Order System version 1.0. The flaw exists in the file /edit_food_items.php, where manipulation of the 'update' argument allows an attacker to inject malicious SQL queries. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a PHP-based web application used for managing food orders. No authentication details are specified, suggesting the attack surface may be broadly accessible. The vulnerability has been assigned CVE-2026-15135 and documented across multiple security databases including NVD and VulDB. Organizations using this system are advised to apply patches or mitigations immediately. The public availability of the exploit significantly elevates the threat level for unpatched deployments.
Technical details
Mitigation steps:
Affected products:
code-projects Online Food Order System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15135
https://code-projects.org/
https://github.com/susususua-AI/CVE/issues/1
https://vuldb.com/cve/CVE-2026-15135
https://vuldb.com/submit/851065
https://vuldb.com/vuln/376951
https://vuldb.com/vuln/376951/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
