A vulnerability was identified in itsourcecode Online...
Moderate severity
Unreviewed
Published
Dec 18, 2025
to the GitHub Advisory Database
•
Updated Dec 18, 2025
Description
Published by the National Vulnerability Database
Dec 17, 2025
Published to the GitHub Advisory Database
Dec 18, 2025
Last updated
Dec 18, 2025
A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
References