Sceawere
Vulnerability Detail
CVE-2026-105171UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Admin Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 18h ago
- Vendor
- kishor-23
- Product
- food-waste-management-system
- Attack Type
- Authorization Bypass
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component Role Attribute Handler. Such manipulation of the argument Name leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T00:16:58.887Z",
"pubdate": "2026-10-05T00:16:58.887Z",
"executiveSummary": "A critical authorization bypass vulnerability has been identified within the kishor-23 food-waste-management-system. The flaw resides in the Role Attribute Handler component, specifically within the admin/admin.php file. By manipulating the 'Name' argument, an unauthenticated remote attacker can circumvent existing access control mechanisms to perform unauthorized administrative actions.\nThe vulnerability stems from improper validation of user-supplied input during role assignment or verification processes. Because the system lacks a formal versioning structure, all identified iterations of the codebase at commit 411989e3ecb82895e53dca7865f72145f03d7d93 and b3a70b2c492dc9904de5be1ad9389bd79b87f82c are considered affected. This flaw poses a significant security risk, as it allows for unauthorized privilege escalation and complete administrative takeover of the affected system endpoints. Given that the exploit code has been disclosed publicly, the risk of active exploitation is high, and the project's lack of response necessitates immediate manual intervention by system administrators to secure the application environment.",
"technicalDetails": "The vulnerability exists due to a failure in the Role Attribute Handler's logic within admin/admin.php, where the 'Name' argument is processed without sufficient server-side validation or authorization checks. In the current implementation, the application trustfully accepts user-provided input to determine authorization roles rather than validating the session context or role identity against a secure, server-side source of truth.\nThe exploitation flow begins with the attacker identifying the target endpoint within the admin/admin.php file. By sending a crafted HTTP request (typically a POST or GET request depending on the specific implementation of the Role Attribute Handler) and manipulating the 'Name' parameter, the attacker can force the application to associate the current session or request with an elevated administrative role. Because the application logic fails to verify if the requesting user holds the authority to invoke administrative functions, the 'Name' parameter acts as a control bypass, allowing the attacker to assume the identity or permissions of an administrator.\nThe attack is remotely executable, requiring no prior authentication or administrative credentials to initiate. Since the system does not enforce strict input sanitization or role-based access control (RBAC) integrity, any remote actor can supply arbitrary strings to the 'Name' argument to manipulate the application's internal authorization state. This behavior is symptomatic of an Insecure Direct Object Reference (IDOR) or a logic error where the authorization decision relies solely on client-side controllable input.\nOnce the authorization check is bypassed, the attacker gains the ability to access restricted system functionalities, potentially leading to unauthorized data exfiltration, system configuration changes, or the management of sensitive food-waste records. The impact is severe as it effectively negates the security perimeter established by the administrative login interface. The absence of versioning implies that this logic error is embedded within the core handling of the application, affecting multiple endpoints that rely on the flawed Role Attribute Handler component to determine user permissions. Post-exploitation, an attacker can maintain persistent administrative access until the session is terminated or the underlying source code is patched to enforce proper session-based authorization validation."
}