Sceawere
Vulnerability Detail
CVE-2026-105166UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Food Donation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 19h ago
- Vendor
- kishor-23
- Product
- food-waste-management-system
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-04T23:16:59.287Z",
"pubdate": "2026-10-04T23:16:59.287Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the kishor-23 food-waste-management-system, specifically within the fooddonateform.php component.\nThe vulnerability allows remote, unauthenticated attackers to manipulate the 'image-choice' argument to execute arbitrary SQL commands against the backend database.\nThe flaw stems from insufficient input sanitization of user-supplied data before incorporating it into database queries, a common risk in web applications that can lead to unauthorized data access, modification, or deletion.\nGiven that the exploit is publicly available and the vendor has not responded to vulnerability disclosure efforts, the risk to deployments is high.\nSuccessful exploitation compromises the integrity and confidentiality of the application's database, potentially allowing an attacker to bypass authentication mechanisms or exfiltrate sensitive information.\nBecause the project utilizes a rolling release model, all current and future deployments running the affected code base are considered vulnerable until remediation is applied.",
"technicalDetails": "The vulnerability resides in the 'insert' function within the 'fooddonateform.php' file of the food-waste-management-system.\nThe root cause is improper neutralization of special elements used in an SQL command (CWE-89), where the application takes input from the 'image-choice' HTTP parameter and directly concatenates it into a database query without adequate validation, escaping, or the use of prepared statements/parameterized queries.\nThe attack flow proceeds as follows: An attacker identifies that the 'image-choice' parameter is processed by the backend 'insert' function in 'fooddonateform.php'. By crafting a malicious payload containing SQL control characters (e.g., single quotes, union operators, or comment sequences), the attacker forces the SQL engine to interpret the input as part of the command structure rather than literal data.\nThe vulnerability is remotely exploitable, requiring no prior authentication. When the application processes the malicious payload, the database executes the injected commands with the privileges assigned to the web application's database user.\nThe impact of this injection can be severe. Depending on the backend database configuration and the privileges of the web user, an attacker may be able to bypass existing authentication mechanisms, perform unauthorized data exfiltration (dumping user tables, donation records, or configuration data), or modify existing data to perform unauthorized actions within the system. Furthermore, in certain database environments, it may be possible to escalate the attack to read/write arbitrary files on the server or execute operating system commands if the database user holds excessive privileges.\nBecause the project follows a rolling release strategy and the repository commit hash 411989e3ecb82895e53dca7865f72145f03d7d93 (and subsequent b3a70b2c492dc9904de5be1ad9389bd79b87f82c) contains the vulnerable logic, any deployment utilizing this code is susceptible. The absence of vendor intervention means that technical mitigations must be applied manually at the application or infrastructure level."
}