CVE-2025-12299
27.10.2025, 17:15
A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
| Vendor | Product | Version |
|---|---|---|
| fabian | simple_food_ordering_system | 1.0 |
𝑥
= Vulnerable software versions