Sceawere

Vulnerability Detail

CVE-2026-105170UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Missing Authentication in Admin Signup

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
18h ago
Vendor
kishor-23
Product
food-waste-management-system
Attack Type
Missing Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T00:16:58.720Z",
  "pubdate": "2026-10-05T00:16:58.720Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Admin Signup component of the kishor-23 food-waste-management-system (commit 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c). The vulnerability is classified as a missing authentication flaw, which allows unauthorized remote actors to bypass security controls during the signup process.\nThe flaw stems from improper input validation and insufficient authentication checks within the admin/signup.php file. By manipulating the 'sign' argument, an unauthenticated attacker can circumvent intended access restrictions. This poses a significant risk to the integrity and confidentiality of the administrative backend, potentially allowing unauthorized individuals to create administrative accounts or gain unauthorized access to system management functions.\nAs the project utilizes a continuous delivery model without distinct versioning, all instances of this codebase are considered potentially vulnerable. The lack of a vendor response further exacerbates the risk, as no official patch is currently available. Threat actors can leverage publicly available exploits to conduct remote attacks against exposed installations, necessitating immediate defensive intervention by system administrators to restrict access to sensitive endpoints.",
  "technicalDetails": "The vulnerability is located within the administrative signup module, specifically in the file admin/signup.php. The root cause of the issue is an insecure implementation of the administrative account registration workflow, where the authentication status is not adequately verified before the application processes the registration request.\nThe attack vector involves manipulating the 'sign' argument sent via an HTTP request to the vulnerable endpoint. Because the application logic fails to perform a server-side check to determine if the requester is authorized to initiate or complete an administrative signup, the system processes the request as if it were a valid, authorized administrative action. This lack of authorization checks effectively bypasses the administrative security perimeter.\nThe attack flow proceeds as follows: An attacker identifies the accessible admin/signup.php endpoint. By crafting a specifically formatted HTTP request that includes the manipulated 'sign' parameter, the attacker forces the underlying PHP script to execute its database insertion logic. Because the input validation routine is either absent or improperly implemented, the script processes the payload and successfully registers a new user with administrative privileges or bypasses existing session restrictions. This does not require prior knowledge of legitimate administrative credentials, as the security check itself is neglected.\nExploitation is possible remotely over the network, as the component is exposed via the web interface. Successful exploitation grants the attacker the ability to interact with administrative features of the food-waste-management-system, leading to full system compromise. Post-exploitation impact includes unauthorized data access, modification of system configurations, and potential persistence mechanisms established through the newly created malicious administrative account. Given that the software employs a rolling release cycle, the vulnerability exists across all deployments currently tracking the affected codebase commit. There are no versioning constraints, making the entire user base susceptible to this flaw until the application code is manually hardened."
}
CVE-2026-105170: Missing Authentication in Admin Signup (HIGH Severity, CVSS: 7.3) | Sceawere