<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Kishor-23 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/kishor-23/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 00:56:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/kishor-23/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in food-waste-management-system</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105166/</link><pubDate>Mon, 05 Oct 2026 00:56:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105166/</guid><description>An unauthenticated SQL injection vulnerability in the 'fooddonateform.php' component of the food-waste-management-system allows remote attackers to execute arbitrary database commands via the 'image-choice' argument.</description><content:encoded><![CDATA[<p>The food-waste-management-system contains a SQL injection vulnerability within the 'insert' function of the 'fooddonateform.php' file. This flaw is triggered when the application fails to properly sanitize the 'image-choice' argument before including it in a database query. A remote attacker can exploit this vulnerability to execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized data access, modification, or deletion. The vulnerability affects the food-waste-management-system repository versions between 411989e3ecb82895e53dca7865f72145f03d7d93 and b3a70b2c492dc9904de5be1ad9389bd79b87f82c. As the project follows a rolling release strategy and lacks a formal patch at this time, users are advised to restrict access to the application or implement web application firewall (WAF) filtering to identify and block malicious input containing SQL syntax in the 'image-choice' parameter.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows remote attackers to compromise the backend database. Depending on the database permissions, this could result in full database exfiltration, modification of application records, or complete application takeover. As the application is intended for food waste management, the impact includes potential data privacy breaches and operational disruption.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor web server logs for exploitation attempts targeting the 'fooddonateform.php' endpoint.</p>
<ul>
<li>Implement input validation rules on the WAF to inspect the 'image-choice' argument for SQL syntax, such as UNION, SELECT, or comment characters.</li>
<li>Audit web server logs for high-frequency requests or requests returning database error messages from 'fooddonateform.php'.</li>
<li>Given the lack of a patch, prioritize network-level isolation or application-level access controls for the food-waste-management-system.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>sql-injection</category><category>vulnerability</category><category>web-application</category></item></channel></rss>