A vulnerability was identified in kishor-23 food-waste...
Low severity
Unreviewed
Published
Oct 5, 2026
to the GitHub Advisory Database
•
Updated Oct 5, 2026
Description
Published by the National Vulnerability Database
Oct 5, 2026
Published to the GitHub Advisory Database
Oct 5, 2026
Last updated
Oct 5, 2026
A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Order Assignment Block. The manipulation of the argument order_id/delivery_person_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
References