admin/donate.php builds the location-filter query from raw POST data and renders the result rows in the HTML table. A UNION SELECT payload returns attacker-chosen values (any database column) directly in the response. The missing exit() after the session redirect makes the handler run without authentication; the result is an anonymous, response-visible SQL injection - no blind techniques needed.
Commit: b3a70b2c492dc9904de5be1ad9389bd79b87f82c
SQL Injection (UNION-based, response-visible; CWE-89)
File: admin/donate.php
$_POST['location'] is placed in the WHERE clause without escaping or prepared statements, and the query output is reflected in the response. The only access control present is a header() redirect without exit() , so unauthenticated requests still reach the vulnerable handler.
Send the filter request without any session cookie and with a UNION payload sized to food_donations (13 columns):
To read other tables, replace the position-2/4/6 values with target columns, e.g. (select password from admin limit 1) ; the value is printed in the name cell. All columns of all tables readable, one query per cell.
Anonymous, response-visible full database disclosure (credentials, feedback PII, donor data) - trivial automation.
Confirms the MySQL context is the root superuser (empty password, see CVE-17).
No session, CSRF token or role verification is involved.
POST /admin/donate.php ( location )
Use prepared statements and validate location against a fixed list (chennai/madurai/coimbatore).
Enforce the admin session with exit() and an explicit role check before any query.
Use a least-privilege database account; htmlspecialchars() output.
Suggested CVSS v3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.8 Critical) - full DB readout at superuser level with unrestricted update access.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
