Sceawere

Vulnerability Detail

CVE-2026-105231UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Admin Registration

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
12h ago
Vendor
kishor-23
Product
food-waste-management-system
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is an unknown function of the file admin/signup.php of the component Admin Registration. The manipulation of the argument email/username/location results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T06:16:57.410Z",
  "pubdate": "2026-10-05T06:16:57.410Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified within the Admin Registration component of the kishor-23 food-waste-management-system (commit 411989e3ecb82895e53dca7865f72145f03d7d93).\nThe vulnerability resides in the admin/signup.php script, where improper input sanitization of user-supplied data allows an unauthenticated or remote attacker to manipulate database queries.\nBy injecting malicious SQL syntax through the 'email', 'username', or 'location' parameters, an attacker can bypass authentication, exfiltrate sensitive database contents, modify application data, or potentially achieve full administrative control over the backend database.\nGiven that the exploit is publicly available and the vendor has not addressed the issue, this poses a severe risk to the confidentiality, integrity, and availability of the system.\nThe product utilizes a rolling release model, meaning no specific version identifiers exist to isolate the impact; all deployments utilizing this codebase are considered potentially vulnerable.",
  "technicalDetails": "The vulnerability is rooted in the insecure handling of user-controllable input within the admin/signup.php file. The application fails to utilize parameterized queries or prepared statements when processing input for the 'email', 'username', and 'location' fields during the administrative registration process.\nThe attack flow begins when an attacker sends a crafted HTTP request to the vulnerable endpoint. By embedding SQL control characters (such as single quotes, semicolons, or comment indicators) into the aforementioned input parameters, the attacker breaks the structural logic of the intended backend SQL command.\nBecause the application concatenates these inputs directly into the query string, the database engine executes the injected SQL commands with the privileges of the database service account. This allows for 'Union-Based' or 'Error-Based' SQL injection, depending on the application's response handling.\nAn attacker can exploit this remotely without requiring prior authentication. The payload typically involves a sequence of SQL commands designed to enumerate table schemas, dump sensitive user data (including hashes of administrator credentials), or manipulate database records. For instance, an attacker could inject ' OR 1=1 -- to alter query logic, effectively bypassing registration constraints or authentication checks entirely.\nThe scope of the vulnerability is significant because it directly interacts with the database layer. Post-exploitation impact includes unauthorized data access, potential escalation of privileges, and in misconfigured database environments, the ability to read/write files on the server or execute operating system commands if the database user possesses sufficient elevated privileges.\nThe current codebase for kishor-23 food-waste-management-system lacks the necessary abstraction layers, such as PDO or MySQLi prepared statements, to prevent this injection. The absence of input validation and sanitization filters allows raw strings to reach the database driver, rendering the system susceptible to standard SQL injection attack patterns."
}
CVE-2026-105231: SQL Injection in Admin Registration (HIGH Severity, CVSS: 7.3) | Sceawere