Skip to content
Food Waste Management System Issues 7

Food Waste Management System Issues 7

github.com • October 5, 2026

admin/donate.php builds the location-filter query from raw POST data and renders the result rows in the HTML table. A UNION SELECT payload returns attacker-chosen values (any database column) directly in the response. The missing exit() after the session redirect makes the handler run without authentication; the result is an anonymous, response-visible SQL injection - no blind techniques needed.

Commit: b3a70b2c492dc9904de5be1ad9389bd79b87f82c

SQL Injection (UNION-based, response-visible; CWE-89)

File: admin/donate.php

$_POST['location'] is placed in the WHERE clause without escaping or prepared statements, and the query output is reflected in the response. The only access control present is a header() redirect without exit() , so unauthenticated requests still reach the vulnerable handler.

Send the filter request without any session cookie and with a UNION payload sized to food_donations (13 columns):

To read other tables, replace the position-2/4/6 values with target columns, e.g. (select password from admin limit 1) ; the value is printed in the name cell. All columns of all tables readable, one query per cell.

Anonymous, response-visible full database disclosure (credentials, feedback PII, donor data) - trivial automation.

Confirms the MySQL context is the root superuser (empty password, see CVE-17).

No session, CSRF token or role verification is involved.

POST /admin/donate.php ( location )

Use prepared statements and validate location against a fixed list (chennai/madurai/coimbatore).

Enforce the admin session with exit() and an explicit role check before any query.

Use a least-privilege database account; htmlspecialchars() output.

Suggested CVSS v3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.8 Critical) - full DB readout at superuser level with unrestricted update access.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (2)