Impact
A flaw exists in the User Registration Endpoint of the Kishor‑23 food‑waste‑management‑system, where unsanitized input from the email, name, and gender parameters can be used to inject arbitrary SQL statements. An attacker who can reach this endpoint can execute malicious queries against the backend database, potentially exfiltrating sensitive user data, modifying records, or causing service disruption. The vulnerability is a classic instance of logic or input handling failure that is captured by CWE‑74 and CWE‑89.
Affected Systems
The affected product is the Kishor‑23 food‑waste‑management‑system, currently developed with a rolling‑release model that does not provide explicit version numbers. Because the commit hashes referenced in the advisory do not map to a publicly released tag, affected installations are those that include the specific code paths in signup.php identified in the advisory, regardless of the release date.
Risk and Exploitability
The CVSS base score is 6.9, indicating moderate severity. The EPSS score is not available, but an exploit has already been made publicly available, and the description states that the attack can be performed remotely. The vulnerability is not listed in the CISA KEV catalog, yet the presence of a public exploit combined with the lack of version obsolescence information means that systems still running the affected code are at a tangible risk of successful injection. The risk is therefore realistic, especially for deployments that have not applied any remediation.
OpenCVE Enrichment