Skip to content
Food Waste Management System Issues 6

Food Waste Management System Issues 6

github.com • October 5, 2026

Unauthenticated time-based blind SQL injection in fooddonateform.php ( image-choice )

fooddonateform.php concatenates the unauthenticated POST parameter image-choice into the donation INSERT without any escaping. Because the login redirect is issued without exit() , the query executes with no session at all. The attacker can run SLEEP() -based boolean payloads to blind-extract database content, or inject subqueries that write data from any table (e.g. admin password hashes) into donation records that are later rendered in the admin panel.

Commit: b3a70b2c492dc9904de5be1ad9389bd79b87f82c

SQL Injection (time-based blind; CWE-89)

File: fooddonateform.php

Only one of the two injections matters: every field is escaped except $category = $_POST['image-choice'] , which is concatenated into the VALUES list raw. Additionally, the access check if($_SESSION['name']==''){ header("location: signin.php"); } never calls exit() , so the form processing continues for anonymous users.

Baseline request — completes immediately:

Injected request — the same no-session request now forces MySQL to sleep for 3 seconds inside the INSERT:

Data exfiltration variant — write server-side values into the new donation row (visible later on admin tables):

No authentication required (redirect without exit() ).

Time-based blind extraction of any table/column (password hashes, feedback PII).

Arbitrary record creation/tampering inside food_donations ; exfiltrated data can be surfaced through the admin tables.

Database user is MySQL root with empty password (CVE-17), so the injected context has superuser privileges.

POST /fooddonateform.php ( image-choice )

Escape $category too (or better, use prepared statements for all fields) and validate it against the fixed allowlist raw-food|cooked-food|packed-food .

Call exit() / die() immediately after every authentication redirect.

Use a least-privilege database account.

Suggested CVSS v3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (2)