CVE-2026-4532

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. It is recommended to change the configuration settings.
References
Link Resource
https://code-projects.org/ Product
https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Simple%20Food%20Ordering%20System%20Information%20Disclosure%20%20.md Exploit Mitigation Third Party Advisory
https://vuldb.com/?ctiid.352320 Permissions Required VDB Entry
https://vuldb.com/?id.352320 Third Party Advisory VDB Entry
https://vuldb.com/?submit.774338 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:carmelo:simple_food_order_system:1.0:*:*:*:*:*:*:*

History

10 Apr 2026, 01:16

Type Values Removed Values Added
CPE cpe:2.3:a:carmelo:simple_food_order_system:1.0:*:*:*:*:*:*:*
First Time Carmelo simple Food Order System
Carmelo
Summary
  • (es) Una vulnerabilidad de seguridad ha sido detectada en code-projects Simple Food Ordering System hasta la versión 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /food/sql/food.sql del componente Gestor de Copias de Seguridad de la Base de Datos. La manipulación conduce a archivos o directorios accesibles. Es posible iniciar el ataque de forma remota. El exploit ha sido divulgado públicamente y puede ser utilizado. Se recomienda cambiar la configuración.
References () https://code-projects.org/ - () https://code-projects.org/ - Product
References () https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Simple%20Food%20Ordering%20System%20Information%20Disclosure%20%20.md - () https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Simple%20Food%20Ordering%20System%20Information%20Disclosure%20%20.md - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.352320 - () https://vuldb.com/?ctiid.352320 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.352320 - () https://vuldb.com/?id.352320 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.774338 - () https://vuldb.com/?submit.774338 - Third Party Advisory, VDB Entry

22 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 02:16

Updated : 2026-04-10 01:16


NVD link : CVE-2026-4532

Mitre link : CVE-2026-4532

CVE.ORG link : CVE-2026-4532


JSON object : View

Products Affected

carmelo

  • simple_food_order_system
CWE
CWE-425

Direct Request ('Forced Browsing')

CWE-552

Files or Directories Accessible to External Parties