CVE-2026-10694: File Inclusion in SourceCodester Online Food Ordering System
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
AI Analysis
Technical Summary
CVE-2026-10694 describes a file inclusion vulnerability in SourceCodester Online Food Ordering System 2.0. The vulnerability exists in the include function of /index.php, where the 'page' argument can be manipulated to include unintended files. This flaw allows remote attackers to potentially execute arbitrary code or disclose sensitive information by including malicious or local files. The vulnerability has a CVSS 4.0 score of 6.9 (medium severity). There is no vendor advisory or patch currently available, and the product is not a cloud service, so remediation depends on the vendor or user applying fixes.
Potential Impact
Successful exploitation of this vulnerability can lead to unauthorized file inclusion, which may result in remote code execution or information disclosure depending on the included files. The vulnerability is remotely exploitable without authentication and requires no user interaction. The medium CVSS score reflects the potential for significant impact but with some limitations in exploit complexity or scope.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the absence of an official fix, users should consider implementing input validation and sanitization on the 'page' parameter to prevent arbitrary file inclusion. Restricting file inclusion to a whitelist of allowed files or disabling dynamic file inclusion altogether can mitigate risk. Monitor vendor channels for updates or patches.
CVE-2026-10694: File Inclusion in SourceCodester Online Food Ordering System
Description
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
CVSS v4.0
Score 6.9medium
Affected software
pkg:github/sourcecodester/online-food-ordering-systemRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-10694 describes a file inclusion vulnerability in SourceCodester Online Food Ordering System 2.0. The vulnerability exists in the include function of /index.php, where the 'page' argument can be manipulated to include unintended files. This flaw allows remote attackers to potentially execute arbitrary code or disclose sensitive information by including malicious or local files. The vulnerability has a CVSS 4.0 score of 6.9 (medium severity). There is no vendor advisory or patch currently available, and the product is not a cloud service, so remediation depends on the vendor or user applying fixes.
Potential Impact
Successful exploitation of this vulnerability can lead to unauthorized file inclusion, which may result in remote code execution or information disclosure depending on the included files. The vulnerability is remotely exploitable without authentication and requires no user interaction. The medium CVSS score reflects the potential for significant impact but with some limitations in exploit complexity or scope.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the absence of an official fix, users should consider implementing input validation and sanitization on the 'page' parameter to prevent arbitrary file inclusion. Restricting file inclusion to a whitelist of allowed files or disabling dynamic file inclusion altogether can mitigate risk. Monitor vendor channels for updates or patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-02T15:47:06.210Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1f765ee29bf47b50276b1c
Added to database: 06/03/2026, 00:33:34 UTC
Last enriched: 06/10/2026, 11:13:21 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.