Sceawere

Vulnerability Detail

CVE-2026-105232UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Food-Waste-Management-System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
12h ago
Vendor
kishor-23
Product
food-waste-management-system
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file delivery/deliverysignup.php of the component Registration Page. This manipulation of the argument username/email/location causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T06:16:57.610Z",
  "pubdate": "2026-10-05T06:16:57.610Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the registration functionality of the kishor-23 food-waste-management-system.\nThe flaw exists within the deliverysignup.php file, specifically affecting the handling of username, email, and location parameters.\nThis vulnerability allows remote, unauthenticated attackers to inject arbitrary SQL commands into the application's backend database.\nSuccessful exploitation can lead to unauthorized data exfiltration, modification of database records, or full compromise of the database management system.\nGiven that the project employs continuous delivery without explicit versioning, all currently deployed instances of this component should be considered vulnerable.\nThe absence of a vendor response increases the risk, as the exploit is publicly available and poses a significant threat to data integrity and confidentiality.",
  "technicalDetails": "The vulnerability originates from improper neutralization of user-supplied data within the deliverysignup.php file of the food-waste-management-system component. The application fails to sanitize or validate inputs for the 'username', 'email', and 'location' parameters before incorporating them into SQL queries.\nThe root cause is the direct concatenation of user-controlled input into database queries, which bypasses the intended query structure. This allows an attacker to manipulate the SQL statement, enabling the injection of malicious SQL commands that the database engine will execute with the privileges of the application's database user.\nThe attack flow begins with a remote request sent to the registration endpoint. An attacker crafts a malicious payload containing SQL syntax (such as UNION SELECT, OR 1=1, or subqueries) designed to alter the query logic. For instance, by injecting a single quote followed by malicious SQL operators into the 'username' field, the attacker can break out of the intended data context.\nBecause the input is processed server-side, the application blindly executes the injected query. This could lead to information schema disclosure, dumping of sensitive user tables, or potentially administrative access bypasses if the registration process performs queries related to authentication or account verification. The scope of the impact is limited only by the permissions of the database user configured for the application.\nThere are no specific version constraints due to the rolling release nature of the deployment model, rendering all deployments of this code base potentially susceptible. The vulnerability does not require authentication, as it resides in the signup process, enabling an unauthenticated remote attacker to interact directly with the backend database via the affected parameters. No sophisticated bypasses are required as the application lacks basic parameterized queries or prepared statements, which are the standard defense against such injection vectors."
}
CVE-2026-105232: SQL Injection in Food-Waste-Management-System (HIGH Severity, CVSS: 7.3) | Sceawere