Impact
The vulnerability resides in an unknown function of deliverymyord.php and allows an attacker to manipulate the delivery_person_id and order_id arguments, leading to a SQL injection flaw. By supplying specially crafted input, an attacker can inject arbitrary SQL statements into the database query. The impact of exploiting this flaw could include unauthorized data exfiltration, modification, or deletion, compromising the confidentiality, integrity, and availability of the system’s data.
Affected Systems
This defect affects the food-waste-management-system product developed by kishor-23. The distribution follows a rolling release model, so no specific version numbers are listed as impacted or fixed.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but it has been publicly disclosed and may be used remotely. The likely attack vector is via the web interface, where an attacker can send crafted requests to the vulnerable script and trigger the injection without additional access requirements.
OpenCVE Enrichment