在 kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c 中发现了一个漏洞。该漏洞影响 Login Flow 组件中的 login.php 文件的某个未知函数。对参数 PHPSESSID 的操纵会导致会话固定攻击(Session Fixation)。该漏洞可被远程利用。相关漏洞利用代码已公开披露,可供使用。该产品未采用版本控制机制
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kishor-23 | food-waste-management-system | 411989e3ecb82895e53dca7865f72145f03d7d93 |
cpe:2.3:a:kishor-23:food-waste-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105229 | 7.3 HIGH | kishor-23 food-waste-management-system User Registration Endpoint signup.php sql injection |
| CVE-2026-105231 | 7.3 HIGH | kishor-23 food-waste-management-system Admin Registration signup.php sql injection |
| CVE-2026-105230 | 7.3 HIGH | kishor-23 food-waste-management-system deliverymyord.php sql injection |
| CVE-2026-105232 | 7.3 HIGH | kishor-23 food-waste-management-system Registration deliverysignup.php sql injection |
No comments yet