Sceawere

Vulnerability Detail

CVE-2026-105169UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Food-Waste-Management-System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
18h ago
Vendor
kishor-23
Product
food-waste-management-system
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument order_id/delivery_person_id results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T00:16:58.547Z",
  "pubdate": "2026-10-05T00:16:58.547Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the kishor-23 food-waste-management-system, specifically within the Take Order Handler component.\nThe vulnerability resides in delivery/delivery.php, where insufficient input sanitization allows for the manipulation of the order_id and delivery_person_id parameters.\nThis flaw enables remote, unauthenticated attackers to execute arbitrary SQL commands against the backend database, potentially leading to unauthorized data extraction, modification, or complete database compromise.\nThe vulnerability is currently publicly disclosed with active exploit code available, posing a significant risk to affected deployments.\nGiven the nature of the rolling release model utilized by the project, no official patches are currently available, and the maintainers have not yet responded to the issue report.\nOrganizations utilizing this system are at high risk, as attackers can leverage this vulnerability to gain control over application data, resulting in a full breach of confidentiality, integrity, and availability.",
  "technicalDetails": "The vulnerability is categorized as a classic SQL injection flaw stemming from improper neutralization of special elements used in an SQL command within the file delivery/delivery.php.\nThe affected component, identified as the Take Order Handler, fails to perform adequate validation or parameterization on the user-supplied input parameters, specifically 'order_id' and 'delivery_person_id'.\nWhen these parameters are processed by the backend PHP script, they are concatenated directly into SQL queries without the use of prepared statements or parameterized queries. This allows an attacker to inject arbitrary SQL syntax into the database engine's query execution process.\nThe attack flow involves an attacker sending a crafted HTTP request to the delivery/delivery.php endpoint. By manipulating the 'order_id' or 'delivery_person_id' arguments with malicious SQL fragments, the attacker can break out of the intended query context.\nExploitation allows for several attack vectors: first, boolean-based or time-based blind SQL injection can be used to infer data from the database structure, such as table names, column names, and sensitive administrative credentials. Second, UNION-based SQL injection may allow for the direct retrieval of database contents within the application's response body. Third, depending on the database configuration and permissions, the attacker may be able to execute administrative functions or perform stacked queries to modify or delete data, escalating the impact to full database takeover.\nBecause the system employs a rolling release model, the specific commit hash range 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c is implicated as the vulnerable codebase. There is no requirement for prior authentication, as the vulnerable script is directly accessible via web request. The attack is fully remote, requiring only network connectivity to the application host. The lack of input sanitization acts as the root cause, and the application's reliance on client-provided data for database operations provides the execution environment for the exploit."
}
CVE-2026-105169: SQL Injection in Food-Waste-Management-System (HIGH Severity, CVSS: 7.3) | Sceawere