Sceawere
Vulnerability Detail
CVE-2026-105167UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Food-Waste-Management-System
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 19h ago
- Vendor
- kishor-23
- Product
- food-waste-management-system
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-04T23:16:59.457Z",
"pubdate": "2026-10-04T23:16:59.457Z",
"executiveSummary": "The Food-Waste-Management-System by kishor-23 contains a SQL injection vulnerability within the admin/donate.php file. This security flaw originates from the improper sanitization of user-supplied input provided via the location argument.\nA remote, unauthenticated attacker can exploit this vulnerability to manipulate SQL queries executed against the backend database. Successful exploitation permits an attacker to perform unauthorized database operations, including the extraction of sensitive data, modification of existing records, or potential administrative bypass.\nGiven that the project utilizes a rolling release system and no official patch has been provided, the risk is elevated. The vulnerability is publicly disclosed, increasing the likelihood of automated exploitation attempts.\nThis issue exposes the underlying data integrity and confidentiality of the application, posing a significant security risk to installations.",
"technicalDetails": "The vulnerability resides in the admin/donate.php file of the Food-Waste-Management-System, specifically within an undefined function handling the 'location' parameter. Analysis indicates that the application fails to utilize parameterized queries or sufficient input validation/sanitization when processing the 'location' argument before incorporating it into a SQL statement.\nThe root cause is a classic SQL injection flaw where untrusted user input is directly concatenated into a backend database query. This allows an attacker to break out of the intended query context by injecting arbitrary SQL syntax.\nThe attack flow proceeds as follows: 1) The attacker identifies the vulnerable 'location' parameter in the admin/donate.php script. 2) The attacker crafts a malicious HTTP request, injecting SQL meta-characters (such as single quotes, comment indicators like -- or #, and SQL keywords) into the 'location' parameter. 3) The backend application receives the payload and executes the tainted SQL command against the database. 4) The database interprets the injected instructions, potentially revealing schema information, dumping table contents, or altering data based on the injected logic.\nThe exploitation is performable remotely without requiring prior authentication, depending on the specific configuration of the administrative interface. Because the vulnerability involves the manipulation of server-side database queries, the post-exploitation impact is severe. An attacker can leverage the injection to perform unauthorized 'SELECT' operations to exfiltrate data, 'UPDATE' or 'DELETE' operations to destroy data integrity, or potentially achieve remote code execution if the database configuration permits interaction with the filesystem (e.g., INTO OUTFILE).\nThe affected codebase encompasses version 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. As a rolling release product, no specific version numbers are defined, implying that any instance running this codebase commit is potentially vulnerable."
}