CVE-2026-103232 Restaurant-Management-System SQL 注入漏洞
影响攻击者可远程注入 SQL 语句,窃取或篡改数据库数据
AdithyaYelloju Restaurant-Management-System 的 admin/table_booking.php 文件中 mysqli_query 函数存在 SQL 注入漏洞。攻击者可通过操纵 Name 参数注入恶意 SQL 语句,且利用代码已公开。该问题已通过 issue 报告告知项目方,但项目方尚未回应。
影响范围
受影响版本为截至提交 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c 的 Restaurant-Management-System,具体版本号暂无公开信息。
漏洞详情
漏洞类型为 SQL 注入。成因是 admin/table_booking.php 中 mysqli_query 调用未对 Name 参数进行充分过滤或参数化处理,导致用户输入被直接拼接进 SQL 语句。攻击者可构造恶意 Name 值改变查询逻辑,从而读取、修改或删除数据库内容,且可远程发起攻击。
利用条件与风险
利用无需认证或仅需低权限即可远程触发,且公开 PoC 已存在,实战中被扫描和利用的风险较高。
修复建议
官方尚未发布修复方案,建议对 Name 参数使用参数化查询或严格输入过滤,并限制 admin 接口访问权限;同时关注项目后续更新。
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.