CVE-2026-105171: medium-severity vulnerability in kishor-23 food-waste-management-system
kishor-23 food-waste-management-system Role Attribute admin.php authorization
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component Role Attribute Handler. Such manipulation of the argument Name leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
kishor-23 · food-waste-management-systempublic PoCs found — 1
cve_referencegithub.com/kishor-23/food-waste-management-system/issues/11unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — kishor-23 food-waste-management-system
In the same product, most dangerous first.
CVE-2026-105170MEDIUMkishor-23 food-waste-management-system Admin Signup signup.php missing authenticationEPSS 0.4%CVE-2026-105167MEDIUMkishor-23 food-waste-management-system donate.php sql injectionEPSS 0.3%CVE-2026-105166MEDIUMkishor-23 food-waste-management-system Food Donation Form fooddonateform.php insert sql injectionEPSS 0.3%CVE-2026-105232MEDIUMkishor-23 food-waste-management-system Registration deliverysignup.php sql injectionEPSS 0.3%CVE-2026-105231MEDIUMkishor-23 food-waste-management-system Admin Registration signup.php sql injectionEPSS 0.3%CVE-2026-105230MEDIUMkishor-23 food-waste-management-system deliverymyord.php sql injectionEPSS 0.3%