Sceawere

Vulnerability Detail

CVE-2026-105230UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in food-waste-management-system

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
12h ago
Vendor
kishor-23
Product
food-waste-management-system
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T06:16:56.120Z",
  "pubdate": "2026-10-05T06:16:56.120Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the kishor-23 food-waste-management-system, specifically within the delivery/deliverymyord.php file.\nThe vulnerability arises due to insufficient sanitization of input arguments, allowing remote attackers to execute arbitrary SQL commands against the backend database.\nThis flaw presents a significant security risk, as it grants unauthorized actors the ability to manipulate database queries, leading to unauthorized data access, modification, or potential database administrative control.\nThe product utilizes a rolling release model, meaning the vulnerability persists across the latest codebase without specific versioning identifiers.\nSince the exploit has been publicly disclosed and the vendor has remained unresponsive to early disclosure reports, the risk of exploitation by malicious actors is high.\nNo authentication is explicitly required to initiate this attack, allowing for remote exploitation over the network.",
  "technicalDetails": "The vulnerability resides within the processing logic of the delivery/deliverymyord.php file. The application fails to properly implement parameterized queries or adequate input validation on the 'delivery_person_id' and 'order_id' arguments.\nWhen these arguments are passed to the server, they are concatenated directly into SQL query strings executed by the database management system. This architectural oversight allows an attacker to break out of the intended query context by injecting crafted SQL syntax into these parameters.\nThe attack flow begins when an attacker sends a malicious HTTP request to the delivery/deliverymyord.php endpoint. By supplying specially crafted payloads—such as UNION-based statements, boolean-based inference strings, or time-based blind injection vectors—into the delivery_person_id or order_id parameters, the attacker instructs the backend database to execute unauthorized operations.\nBecause the input is not treated as data, but rather as executable code, the database engine interprets the malicious input as part of the SQL instruction. This enables the attacker to bypass access controls, extract sensitive information stored in the database tables, or potentially escalate privileges if the database user permissions are overly permissive.\nExploitation does not require prior authentication or elevated system privileges, making it a viable target for remote, unauthenticated adversaries. Since the application provides continuous delivery, the lack of version control ensures that the vulnerable code remains in production until specifically patched. The absence of a formal vendor response leaves the current codebase exposed to potential automated exploitation attempts given the public availability of the vulnerability disclosure."
}
CVE-2026-105230: SQL Injection in food-waste-management-system (HIGH Severity, CVSS: 7.3) | Sceawere