Impact
The vulnerability lies in the Role Attribute Handler component of the open‑source food‑waste‑management‑system, where manipulating the 'Name' parameter in admin/admin.php allows a remote attacker to bypass role checks and gain unauthorized administrative privileges. This flaw is exemplified by the CWE‑285 (Authorization Bypass Through Privilege Escalation) and CWE‑639 (Authorization Bypass by User Controllable Input) weaknesses.
Affected Systems
All deployments of kishor‑23's food‑waste‑management‑system that include the admin/admin.php endpoint are affected. The product does not employ version numbers and the vulnerable commit hash is listed in the public repository, indicating that any instance built from that commit is susceptible. No mitigation or patch version is publicly identified, so every active installation poses a risk.
Risk and Exploitability
The CVSS score of 5.3 places the flaw in the medium severity range, and while the EPSS score is not available, the attack is described as remotely achievable with publicly disclosed exploit code. Because there is no matching KEV listing, the likelihood of widespread exploitation is uncertain, yet the remote nature and the lack of an effective countermeasure warrant prompt action. An attacker can use a crafted HTTP request to supply a custom 'Name' value, overriding role validation and accomplishing unauthorized access without needing elevated credentials.
OpenCVE Enrichment