天下漏洞,尽知其名
HIGH

CVE-2026-103230 Restaurant-Management-System SQL 注入漏洞

影响攻击者可远程注入 SQL 语句,窃取或篡改数据库数据

AI 研判

AdithyaYelloju Restaurant-Management-System 的 User/ord.php 文件中,Order Placement 组件的 mysqli_query 函数对 id/name 参数处理不当,存在 SQL 注入漏洞。攻击者可远程利用该漏洞执行任意 SQL 语句,且利用代码已公开披露。

影响范围

AdithyaYelloju Restaurant-Management-System

受影响版本为截至提交 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c 的 Restaurant-Management-System,具体版本号暂无公开信息。

漏洞详情

漏洞类型为 SQL 注入,成因是 User/ord.php 中 mysqli_query 函数直接拼接用户可控的 id/name 参数,未进行过滤或参数化处理。攻击者可通过构造恶意 SQL 语句,远程注入并执行数据库操作,从而读取、修改或删除敏感数据。

利用条件与风险

利用前提是攻击者能访问 User/ord.php 并控制 id/name 参数,无需认证即可远程发起攻击。由于利用代码已公开,实战风险较高,可能导致数据泄露或业务中断。

修复建议

官方尚未发布修复方案,建议对 id/name 参数使用参数化查询或严格过滤,并限制该接口的访问权限。临时缓解措施包括部署 WAF 拦截 SQL 注入攻击,或暂时禁用受影响功能。

原始情报

A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.