Skip to content
Threat Feed
high advisory

SQL Injection Vulnerability in food-waste-management-system

An unauthenticated SQL injection vulnerability in the 'fooddonateform.php' component of the food-waste-management-system allows remote attackers to execute arbitrary database commands via the 'image-choice' argument.

CVE search metadata

CVE search record: CVE-2026-105166. Severity: high. CVSS: 7.3. KEV: no. Product: food-waste-management-system (411989e3ecb82895e53dca7865f72145f03d7d93 to b3a70b2c492dc9904de5be1ad9389bd79b87f82c), food-waste-management-system. Brief: SQL Injection Vulnerability in food-waste-management-system. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105166/

What's new

  • 1. added detection rule: Detects CVE-2026-105169 Exploitation - SQL Injection in delivery.php Oct 5, 00:56 via nvd

The food-waste-management-system contains a SQL injection vulnerability within the 'insert' function of the 'fooddonateform.php' file. This flaw is triggered when the application fails to properly sanitize the 'image-choice' argument before including it in a database query. A remote attacker can exploit this vulnerability to execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized data access, modification, or deletion. The vulnerability affects the food-waste-management-system repository versions between 411989e3ecb82895e53dca7865f72145f03d7d93 and b3a70b2c492dc9904de5be1ad9389bd79b87f82c. As the project follows a rolling release strategy and lacks a formal patch at this time, users are advised to restrict access to the application or implement web application firewall (WAF) filtering to identify and block malicious input containing SQL syntax in the 'image-choice' parameter.

Impact

Successful exploitation of this vulnerability allows remote attackers to compromise the backend database. Depending on the database permissions, this could result in full database exfiltration, modification of application records, or complete application takeover. As the application is intended for food waste management, the impact includes potential data privacy breaches and operational disruption.

Recommendation

Detection engineering teams should monitor web server logs for exploitation attempts targeting the 'fooddonateform.php' endpoint.

  • Implement input validation rules on the WAF to inspect the 'image-choice' argument for SQL syntax, such as UNION, SELECT, or comment characters.
  • Audit web server logs for high-frequency requests or requests returning database error messages from 'fooddonateform.php'.
  • Given the lack of a patch, prioritize network-level isolation or application-level access controls for the food-waste-management-system.

Immediate actions

Review infrastructure for the presence of kishor-23 food-waste-management-system

SOC 24h

Mitigations

Restrict external access to fooddonateform.php or apply WAF filtering

immediate IT Operations

CVE-2026-105166

Detection coverage 2

Detect CVE-2026-105166 Exploitation - SQL Injection in fooddonateform.php

high

Detects exploitation attempts against the food-waste-management-system where the 'image-choice' argument contains SQL injection characters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detects CVE-2026-105169 Exploitation - SQL Injection in delivery.php

high

Detects exploitation attempts targeting CVE-2026-105169 where SQL injection patterns are passed to delivery.php

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →