Sceawere

Vulnerability Detail

CVE-2026-105168UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Order Assignment

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
18h ago
Vendor
kishor-23
Product
food-waste-management-system
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Order Assignment Block. The manipulation of the argument order_id/delivery_person_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T00:16:58.373Z",
  "pubdate": "2026-10-05T00:16:58.373Z",
  "executiveSummary": "A SQL injection vulnerability exists within the Order Assignment Block of the kishor-23 food-waste-management-system.\nThe vulnerability originates from improper neutralization of user-supplied input in the admin/admin.php file, specifically targeting the order_id and delivery_person_id arguments.\nThis flaw allows remote, unauthenticated or authenticated attackers to manipulate backend database queries, potentially leading to unauthorized data access, modification, or complete database compromise.\nThe product utilizes a rolling release model, meaning the vulnerability is present in the specified commit hashes (411989e3ecb82895e53dca7865f72145f03d7d93 and b3a70b2c492dc9904de5be1ad9389bd79b87f82c) and potentially current versions.\nGiven that proof-of-concept exploit code is publicly available, the risk to deployments is high.\nThe vendor has been notified via an issue report but has not addressed the security flaw, necessitating proactive defense by system administrators.",
  "technicalDetails": "The vulnerability is a classic SQL injection (SQLi) occurring in the Order Assignment Block of the food-waste-management-system. The root cause is the insecure handling of HTTP GET or POST parameters, specifically 'order_id' and 'delivery_person_id', within the administrative interface located at 'admin/admin.php'.\nThe application fails to employ parameterized queries or prepared statements when interacting with the database. Consequently, the input provided by the user is concatenated directly into SQL command strings. This allows an attacker to inject arbitrary SQL syntax, effectively altering the logic of the database query executed by the application.\nThe attack flow begins with the attacker crafting a malicious payload within the vulnerable parameters. By submitting a request to 'admin/admin.php' containing SQL meta-characters (such as single quotes, comments, or union operators), the attacker forces the database to interpret the injected string as part of the command structure. For example, by manipulating the 'order_id', an attacker can bypass authorization checks, extract data from other tables, or potentially escalate privileges by modifying the database schema or administrative credentials.\nSince the vulnerability is located in an administrative script, the potential for impact is significant. Exploitation can lead to full database enumeration, unauthorized data exfiltration of sensitive information, or disruption of service. As the application is exposed remotely, the attack vector is accessible over the network, and the lack of proper input validation or sanitization ensures that these inputs are treated as trusted data.\nWhile the specific database engine is not explicitly identified, the nature of the flaw suggests a standard relational database management system. Without strict input casting (e.g., forcing parameters to integers) or the implementation of an abstraction layer utilizing prepared statements, the 'admin.php' component remains inherently vulnerable to various SQLi techniques, including UNION-based and blind SQL injection. The availability of a public exploit simplifies the exploitation process, allowing attackers to leverage automated tools to identify the injection point and extract database contents with minimal effort."
}
CVE-2026-105168: SQL Injection in Order Assignment (MEDIUM Severity, CVSS: 6.3) | Sceawere