CVE-2026-103231 Restaurant-Management-System SQL 注入漏洞
影响攻击者可远程注入 SQL 语句,窃取或篡改数据库数据
AdithyaYelloju Restaurant-Management-System 的 User/cancel.php 文件中 mysqli_query 函数对 ID 参数处理不当,存在 SQL 注入漏洞。该漏洞可被远程利用,且已有公开的利用代码。项目方已通过 issue 报告获知该问题,但尚未作出回应。
影响范围
受影响版本为截至提交 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c 的 Restaurant-Management-System,具体版本号暂无公开信息。
漏洞详情
漏洞类型为 SQL 注入。成因是 User/cancel.php 中 mysqli_query 函数直接拼接用户可控的 ID 参数,未做参数化或转义处理。攻击者可通过构造恶意 ID 值远程注入 SQL 语句,从而读取、修改或删除数据库中的敏感数据。
利用条件与风险
利用前提是目标系统暴露可访问的 User/cancel.php 接口,且攻击者能控制 ID 参数。由于利用代码已公开,实战中被扫描和攻击的风险较高。
修复建议
官方尚未发布修复方案,建议关注项目仓库更新。临时缓解措施包括对 ID 参数进行严格校验与参数化查询、限制该接口的访问权限,或部署 WAF 拦截 SQL 注入攻击。
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.