Sceawere
Vulnerability Detail
CVE-2026-105232UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Food-Waste-Management-System
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 12h ago
- Vendor
- kishor-23
- Product
- food-waste-management-system
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file delivery/deliverysignup.php of the component Registration Page. This manipulation of the argument username/email/location causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T06:16:57.610Z",
"pubdate": "2026-10-05T06:16:57.610Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in the registration functionality of the kishor-23 food-waste-management-system.\nThe flaw exists within the deliverysignup.php file, specifically affecting the handling of username, email, and location parameters.\nThis vulnerability allows remote, unauthenticated attackers to inject arbitrary SQL commands into the application's backend database.\nSuccessful exploitation can lead to unauthorized data exfiltration, modification of database records, or full compromise of the database management system.\nGiven that the project employs continuous delivery without explicit versioning, all currently deployed instances of this component should be considered vulnerable.\nThe absence of a vendor response increases the risk, as the exploit is publicly available and poses a significant threat to data integrity and confidentiality.",
"technicalDetails": "The vulnerability originates from improper neutralization of user-supplied data within the deliverysignup.php file of the food-waste-management-system component. The application fails to sanitize or validate inputs for the 'username', 'email', and 'location' parameters before incorporating them into SQL queries.\nThe root cause is the direct concatenation of user-controlled input into database queries, which bypasses the intended query structure. This allows an attacker to manipulate the SQL statement, enabling the injection of malicious SQL commands that the database engine will execute with the privileges of the application's database user.\nThe attack flow begins with a remote request sent to the registration endpoint. An attacker crafts a malicious payload containing SQL syntax (such as UNION SELECT, OR 1=1, or subqueries) designed to alter the query logic. For instance, by injecting a single quote followed by malicious SQL operators into the 'username' field, the attacker can break out of the intended data context.\nBecause the input is processed server-side, the application blindly executes the injected query. This could lead to information schema disclosure, dumping of sensitive user tables, or potentially administrative access bypasses if the registration process performs queries related to authentication or account verification. The scope of the impact is limited only by the permissions of the database user configured for the application.\nThere are no specific version constraints due to the rolling release nature of the deployment model, rendering all deployments of this code base potentially susceptible. The vulnerability does not require authentication, as it resides in the signup process, enabling an unauthenticated remote attacker to interact directly with the backend database via the affected parameters. No sophisticated bypasses are required as the application lacks basic parameterized queries or prepared statements, which are the standard defense against such injection vectors."
}