A vulnerability described as critical has been identified in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of the argument cname leads to sql injection.

This vulnerability is referenced as CVE-2025-11600. It is possible to launch the attack remotely. Furthermore, an exploit is available.