CVE-2019-18417: Sourcecodester Restaurant Management System

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.

Affected products

Published 2019-10-24. Last modified 2026-06-17.