Impact
A vulnerability in Pet Shop Management System allows remote attackers to inject arbitrary SQL through the ID argument in admin_reject_completed.php. This type of flaw, categorized as CWE-74 and CWE-89, lets attackers alter or retrieve database content, potentially exposing sensitive business data or tampering with records. The injection can be triggered from an external source, enabling unauthorized read or write operations against the underlying database.
Affected Systems
The affected product is the Pet Shop Management System developed by itsourcecode, version 1.0. The vulnerability resides in an undefined function within admin_reject_completed.php. No additional sub‑versions are listed; applications built from this baseline remain susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit this flaw remotely by supplying malicious ID values through an exposed URL or form. Because the flaw directly interprets user input into a SQL statement, the likelihood of successful exploitation is high if the application does not sanitize the parameter. The impact, if successful, includes data exposure and potential data modification.
OpenCVE Enrichment