CVE-2026-5017 | code-projects Simple Food Order System 1.0 Parameter /all-tickets.php Status sql injection
A vulnerability identified as critical has been detected in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection.
This vulnerability is identified as CVE-2026-5017. The attack can be initiated remotely. Additionally, an exploit exists.