CVE-2026-103231
Deferred Deferred - Pending Action

SQL Injection in Restaurant Management System via Order Cancellation

Vulnerability report for CVE-2026-103231, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
adithyayelloju restaurant_management_system to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c (inc)
adithyayelloju restaurant-management-system to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated SQL injection in the Restaurant-Management-System project. It exists in the User/cancel.php file where the 'id' GET parameter is directly used in SQL DELETE statements without proper validation or escaping. Attackers can exploit this by injecting malicious SQL payloads via crafted URLs to delete all records in the order_list or t_order tables.

Detection Guidance

To detect this SQL injection vulnerability, inspect the User/cancel.php and User/cancel_t.php files for direct concatenation of the 'id' GET parameter into SQL DELETE statements without proper escaping or validation. Check for code patterns like 'DELETE FROM order_list WHERE id=\'$id\'' or similar. Use network monitoring tools to detect unusual DELETE requests with SQL payloads in the 'id' parameter.

Impact Analysis

This vulnerability allows remote attackers to delete all order data in the system by exploiting the SQL injection flaw. This could disrupt restaurant operations, cause data loss, and potentially lead to further attacks like remote code execution. The exploit is publicly available and can be initiated without authentication.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized data deletion and potential exposure of sensitive customer information. GDPR requires protection of personal data, and HIPAA mandates safeguarding health-related data. The loss of order data may violate these regulations.

Mitigation Strategies

Immediately update the Restaurant-Management-System to a patched version if available. If not, modify the User/cancel.php and User/cancel_t.php files to use prepared statements with parameterized queries instead of direct variable interpolation. Ensure proper input validation and sanitization for the 'id' parameter. Implement authentication and authorization checks to prevent unauthenticated access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103231. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart