Vendor
An unauthenticated SQL injection vulnerability in the 'fooddonateform.php' component of the food-waste-management-system allows remote attackers to execute arbitrary database commands via the 'image-choice' argument.