CVE-2026-105170: kishor-23 food-waste-management-system Admin Signup signup.php missing authentication
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker can initiate the attack. No existing account or user interaction is indicated as necessary.
Is public exploit code available?
Yes. The exploit has been made publicly available and could be used in attacks.
Which releases are affected or fixed?
The product uses continuous delivery with rolling releases, so affected and updated version details are not available. The identified affected code is in admin/signup.php in the referenced revisions.
Has the vendor addressed the issue?
The project was notified through an issue report but had not responded at the time of the report. No fix information is provided.