CVE-2026-105171: fallo de gravedad media en kishor-23 food-waste-management-system
kishor-23 food-waste-management-system Role Attribute admin.php authorization
Publicada el · Actualizada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.2%
probabilidad de explotación
0.2%top 89% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component Role Attribute Handler. Such manipulation of the argument Name leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
kishor-23 · food-waste-management-systemPoCs públicas encontradas — 1
cve_referencegithub.com/kishor-23/food-waste-management-system/issues/11no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — kishor-23 food-waste-management-system
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-105170MEDIUMkishor-23 food-waste-management-system Admin Signup signup.php missing authenticationEPSS 0.4%CVE-2026-105167MEDIUMkishor-23 food-waste-management-system donate.php sql injectionEPSS 0.3%CVE-2026-105166MEDIUMkishor-23 food-waste-management-system Food Donation Form fooddonateform.php insert sql injectionEPSS 0.3%CVE-2026-105232MEDIUMkishor-23 food-waste-management-system Registration deliverysignup.php sql injectionEPSS 0.3%CVE-2026-105231MEDIUMkishor-23 food-waste-management-system Admin Registration signup.php sql injectionEPSS 0.3%CVE-2026-105230MEDIUMkishor-23 food-waste-management-system deliverymyord.php sql injectionEPSS 0.3%