Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
HIGH severity

CVE-2026-103230 — Restaurant-Management-System

HIGH

CVE-2026-103230 is a high-severity (CVSS 7.3) CWE-74 vulnerability in adithyayelloju restaurant-management-system. No vendor fix is recorded yet; mitigation options are listed below.

A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php…

Published
Sep 30, 2026
Updated
Sep 30, 2026
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Description

A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Affected Products

1 product · 1 configurations
Application
restaurant-management-systemadithyayelloju
all

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every adithyayelloju restaurant-management-system deployment and check each version against the affected-products list above.

  2. Remediation status

    No patch has shipped for CVE-2026-103230 yet — track the adithyayelloju restaurant-management-system advisory for a fixed release and apply the workarounds below in the meantime.

  3. Mitigate without a patch

    Until you can upgrade, make sure every query built from user input uses parameterised statements or a prepared-statement API rather than string concatenation, and reduce the database account's privileges so an injected query cannot read or alter data beyond what the feature needs. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Frequently Asked Questions

A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
O3 Security · Runtime Protection

Is CVE-2026-103230 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2026-103230: SQL Injection (High 7.3) | O3 Security