CVE-2026-105230: kishor-23 food-waste-management-system deliverymyord.php sql injection
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument deliverypersonid/orderid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is remotely exploitable and requires no privileges or user interaction. An attacker able to send requests to the affected delivery/deliverymyord.php endpoint can manipulate the delivery_person_id or order_id arguments.
Are fixed versions available?
No affected or updated release versions are available because the project uses a rolling-release delivery model. The project was reportedly notified through an issue report but had not responded.
What should teams do if they cannot patch immediately?
Restrict public access to the affected endpoint where possible, and block or tightly validate requests containing delivery_person_id and order_id. Monitor requests to delivery/deliverymyord.php for suspicious parameter values indicative of SQL injection attempts.
How urgent is remediation?
The vulnerability is rated high severity with a 7.3 score, and public exploit information has been disclosed. Confidentiality, integrity, and availability impacts are each rated low.