SourceCodester Online Food Ordering System Create an Account Page index.php cross site scripting
Description
A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting vulnerability in SourceCodester Online Food Ordering System 2.0 via First Name/Last Name on registration page, allowing remote unauthenticated attackers to execute arbitrary scripts.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System version 2.0 [1]. The issue occurs in the Create an Account page of index.php, where the First Name and Last Name parameters are not properly sanitized. This allows an attacker to inject malicious JavaScript code into the application.
Exploitation
An unauthenticated attacker can exploit this vulnerability remotely by submitting a crafted registration request with malicious script payloads in either the First Name or Last Name fields. No special privileges or user interaction are required beyond submitting the form.
Impact
Successful exploitation leads to stored XSS, meaning the injected script is saved and executed when other users (including administrators) view the stored data. This could result in session hijacking, credential theft, defacement, or unauthorized actions performed on behalf of the victim.
Mitigation
As of the publication date (September 9, 2024), no official patch has been released by the vendor for version 2.0. Mitigation measures include implementing input validation and output encoding for all user-supplied data, using a Content Security Policy (CSP) to restrict script execution, and considering upgrading to a fixed version if available in the future. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =2.0
- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- vuldb.commitrethird-party-advisory
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
- www.sourcecodester.commitreproduct
News mentions
0No linked articles in our index yet.