CyberRota Analysis
AI-GeneratedA SQL injection vulnerability exists in the User Registration Endpoint of the kishor-23 food-waste-management system, specifically in the processing of the signup.php file, allowing remote attackers to manipulate parameters such as email, name, or gender. This high-severity flaw (CVSS 7.3) could lead to unauthorized access to sensitive data or further exploitation of the system. Organizations using this food-waste-management system should prioritize immediate remediation, as the exploit is publicly available and could be leveraged in attacks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.