Description
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in an unknown function of deliverymyord.php and allows an attacker to manipulate the delivery_person_id and order_id arguments, leading to a SQL injection flaw. By supplying specially crafted input, an attacker can inject arbitrary SQL statements into the database query. The impact of exploiting this flaw could include unauthorized data exfiltration, modification, or deletion, compromising the confidentiality, integrity, and availability of the system’s data.

Affected Systems

This defect affects the food-waste-management-system product developed by kishor-23. The distribution follows a rolling release model, so no specific version numbers are listed as impacted or fixed.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but it has been publicly disclosed and may be used remotely. The likely attack vector is via the web interface, where an attacker can send crafted requests to the vulnerable script and trigger the injection without additional access requirements.

Generated by OpenCVE AI on October 5, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a patch or upgrade to a fixed release when it becomes available from the vendor
  • Restrict or disable public access to deliverymyord.php or enforce strict input validation on delivery_person_id and order_id parameters
  • Implement web application firewall rules to detect and block SQL injection patterns against the affected script

Generated by OpenCVE AI on October 5, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title kishor-23 food-waste-management-system deliverymyord.php sql injection
First Time appeared Kishor-23
Kishor-23 food-waste-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:kishor-23:food-waste-management-system:*:*:*:*:*:*:*:*
Vendors & Products Kishor-23
Kishor-23 food-waste-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Kishor-23 Food-waste-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T05:00:16.888Z

Reserved: 2026-10-04T13:58:14.271Z

Link: CVE-2026-105230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T06:16:56.120

Modified: 2026-10-05T06:16:56.120

Link: CVE-2026-105230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T06:30:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')