在 kishor-23 食物废物管理系统(版本标识:411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c)中发现了一个安全漏洞。该漏洞影响了“取餐处理程序”(Take Order Handler)组件中 delivery/delivery.php 文件的某个未知函数。通过对参数 order_id/delivery_person_id 的操作,可触发 SQL 注入攻击。攻击者可在远程发起利用。该漏洞的利用代码
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kishor-23 | food-waste-management-system | 411989e3ecb82895e53dca7865f72145f03d7d93 |
cpe:2.3:a:kishor-23:food-waste-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105166 | 7.3 HIGH | kishor-23 food-waste-management-system Food Donation Form fooddonateform.php insert sql in |
| CVE-2026-105167 | 7.3 HIGH | kishor-23 food-waste-management-system donate.php sql injection |
| CVE-2026-105170 | 7.3 HIGH | kishor-23 food-waste-management-system Admin Signup signup.php missing authentication |
| CVE-2026-105168 | 6.3 MEDIUM | kishor-23 food-waste-management-system Order Assignment Block admin.php sql injection |
| CVE-2026-105171 | 6.3 MEDIUM | kishor-23 food-waste-management-system Role Attribute admin.php authorization |
No comments yet