SQL Injection Vulnerability in Food Donation Form of Kishor-23 Food Waste Management System
CVE-2026-105166
Key Information:
- Vendor
Kishor-23
- Vendor
- CVE Published:
- 4 October 2026
Badges
What is CVE-2026-105166?
A SQL injection vulnerability exists in the Food Donation Form within the Kishor-23 Food Waste Management System, specifically in the insert function of the fooddonateform.php file. This flaw arises from improper handling of user inputs, particularly the 'image-choice' argument. Attackers can exploit this vulnerability remotely, potentially gaining unauthorized access to the system's database. Despite early notification of the issue through a report, the vendor has yet to respond, leaving users susceptible to this public exploit.
Affected Version(s)
food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93
food-waste-management-system b3a70b2c492dc9904de5be1ad9389bd79b87f82c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
