CVE-2026-105232: kishor-23 food-waste-management-system Registration deliverysignup.php sql injection
A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file delivery/deliverysignup.php of the component Registration Page. This manipulation of the argument username/email/location causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction. Exploitation involves manipulating the username, email, or location arguments submitted to the delivery registration page.
Is there a known fixed release?
No affected or updated version details are available because the project uses continuous delivery with rolling releases. The project was reportedly notified through an issue report but had not responded.
How likely is exploitation in practice?
An exploit has been published and may be used. This increases the likelihood of exploitation for deployments that expose the affected delivery registration functionality.