Description
A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2025-12-17: | Advisory disclosed |
| 2025-12-17: | VulDB entry created |
| 2025-12-17: | VulDB entry last update |
Credits
Yu Zhang (VulDB User)
References
github.com/ZhangYu-del/cve/issues/1
vuldb.com/?id.336981 (VDB-336981 | itsourcecode Online Cake Ordering System updateproduct.php sql injection)
vuldb.com/?ctiid.336981 (VDB-336981 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.715063 (Submit #715063 | itsourcecode Online Cake Ordering System V1.0 SQL Injection)
github.com/ZhangYu-del/cve/issues/1
itsourcecode.com/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.