Description
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Assess Impact
AI Analysis

Impact

A flaw exists in the User Registration Endpoint of the Kishor‑23 food‑waste‑management‑system, where unsanitized input from the email, name, and gender parameters can be used to inject arbitrary SQL statements. An attacker who can reach this endpoint can execute malicious queries against the backend database, potentially exfiltrating sensitive user data, modifying records, or causing service disruption. The vulnerability is a classic instance of logic or input handling failure that is captured by CWE‑74 and CWE‑89.

Affected Systems

The affected product is the Kishor‑23 food‑waste‑management‑system, currently developed with a rolling‑release model that does not provide explicit version numbers. Because the commit hashes referenced in the advisory do not map to a publicly released tag, affected installations are those that include the specific code paths in signup.php identified in the advisory, regardless of the release date.

Risk and Exploitability

The CVSS base score is 6.9, indicating moderate severity. The EPSS score is not available, but an exploit has already been made publicly available, and the description states that the attack can be performed remotely. The vulnerability is not listed in the CISA KEV catalog, yet the presence of a public exploit combined with the lack of version obsolescence information means that systems still running the affected code are at a tangible risk of successful injection. The risk is therefore realistic, especially for deployments that have not applied any remediation.

Generated by OpenCVE AI on October 5, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the most recent release of the food‑waste‑management‑system, which is the recommended approach given the rolling‑release model but must be verified by checking the repository for any patches to signup.php.
  • Implement parameterized queries or ORM‑based database access for all user‑supplied input, particularly email, name, and gender, to eliminate the injection vector.
  • If an immediate upgrade is not possible, deploy a web‑application firewall or input‑validation layer that sanitizes or blocks suspicious SQL fragments before they reach the database.

Generated by OpenCVE AI on October 5, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Title kishor-23 food-waste-management-system User Registration Endpoint signup.php sql injection
First Time appeared Kishor-23
Kishor-23 food-waste-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:kishor-23:food-waste-management-system:*:*:*:*:*:*:*:*
Vendors & Products Kishor-23
Kishor-23 food-waste-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Kishor-23 Food-waste-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T04:45:13.938Z

Reserved: 2026-10-04T13:58:09.179Z

Link: CVE-2026-105229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T05:17:03.260

Modified: 2026-10-05T05:17:03.260

Link: CVE-2026-105229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T06:30:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')