Impact
A flaw exists in the delivery signup module of the food-waste-management-system, allowing an attacker to manipulate the username, email, or location input to inject arbitrary SQL statements. The injection vulnerability is a classic SQL injection (CWE-74 and CWE-89) that can be triggered over the network. The vendor has not responded to the issue and a public exploit is available, meaning the flaw is actively considered exploitable.
Affected Systems
The vulnerability affects the kishor-23 food-waste-management-system. No version number is specified because the project uses continuous delivery and the affected commit is identified only by its hash. The issue involves an unknown function within delivery/deliverysignup.php and specifically targets the username, email, and location parameters.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium to high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, so an unauthenticated external attacker can exploit the flaw from any network location. Because the exploit is published and the project has not provided a fix, the risk is ongoing until the vendor releases a patched version or the vulnerability is remediated manually.
OpenCVE Enrichment