SQL Injection Vulnerability in Kishor-23 Food Waste Management System
CVE-2026-105169
Key Information:
- Vendor
Kishor-23
- Vendor
- CVE Published:
- 4 October 2026
Badges
What is CVE-2026-105169?
A security issue has been uncovered in the Kishor-23 Food Waste Management System, specifically in the Take Order Handler's delivery.php file. The vulnerability arises from improper handling of parameters such as order_id and delivery_person_id, leading to potential SQL injection attacks. This flaw allows attackers to execute arbitrary SQL code remotely, posing a significant risk to data integrity and confidentiality. Although the project has been alerted to this issue, no resolution has been communicated as of now. The absence of version-specific details complicates the mitigation process, making it imperative for users to assess their exposure to this vulnerability.
Affected Version(s)
food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93
food-waste-management-system b3a70b2c492dc9904de5be1ad9389bd79b87f82c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
