CVE-2026-4472 identifies a critical SQL Injection vulnerability in itsourcecode Online Frozen Foods Ordering System version 1.0. This flaw specifically affects the /admin/admin_edit_supplier.php file, where manipulation of the 'Supplier_Name' argument allows for remote injection. With a CVSS score of 9.8 (Critical), the vulnerability presents a low-complexity attack vector that can lead to a complete compromise of confidentiality, integrity, and availability. Although the exploit has been publicly disclosed, there is currently no evidence of active exploitation, widely available exploit modules in common frameworks, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:adonesevangelista:online_frozen_foods_ordering_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.