CVE-2025-2387 | SourceCodester Online Food Ordering System 2.0 ajax.php?action=add_to_cart pid sql injection
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection.
This vulnerability is traded as CVE-2025-2387. It is possible to launch the attack remotely. Furthermore, there is an exploit available.