CVE-2026-14622

Source
https://cve.org/CVERecord?id=CVE-2026-14622
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14622.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14622
Published
2026-07-04T08:45:08Z
Modified
2026-10-08T02:50:39Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
Details

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14622.json"
}
References

Affected packages

Git / github.com/jairiidriss/restaurant-website-php-mysql

Affected ranges

Type
GIT
Repo
https://github.com/jairiidriss/restaurant-website-php-mysql
Events

Affected versions

Other
521428b5b612449df0cf4a5d15ee40cba67f3d35

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14622.json"