Skip to content
ThreatCluster

Critical LFI Vulnerability in Food-Ordering-1.0 Exposed

First seen 27 Sep 2026, 19:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:57 UTC
  • •LFI vulnerability allows unauthorized file access.
  • •Exploits involve manipulating POST request parameters.
  • •No patches or fixes have been released yet.

A Local File Inclusion (LFI) vulnerability was discovered in Food-Ordering-1.0 software, allowing authenticated users to manipulate parameters like id=30. This flaw can lead to directory traversal, unauthorized access to sensitive files, or full server compromise. The vulnerability was reported by nu11secur1ty on September 23, 2026, and is classified as high severity. The attack vector involves sending specially crafted POST requests to the update_category.php endpoint, which lacks proper input sanitization. The potential impact includes unauthorized access to sensitive data and server control. The vulnerability affects systems running the Food-Ordering-1.0 application. No patches or fixes have been mentioned in the articles. The current status indicates that the vulnerability is known but not yet exploited in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
LFI vulnerability reported
nu11secur1ty disclosed a Local File Inclusion vulnerability in Food-Ordering-1.0 affecting authenticated users.
Cxsecurity
2026-09-26
Two articles published
Two articles were published on the same day reporting the same LFI vulnerability in Food-Ordering-1.0.
Cxsecurity

More articles in this cluster (2)