Description
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Compromise via SQL Injection
Action: Apply Patch
AI Analysis

Impact

A vulnerability in Pet Shop Management System allows remote attackers to inject arbitrary SQL through the ID argument in admin_reject_completed.php. This type of flaw, categorized as CWE-74 and CWE-89, lets attackers alter or retrieve database content, potentially exposing sensitive business data or tampering with records. The injection can be triggered from an external source, enabling unauthorized read or write operations against the underlying database.

Affected Systems

The affected product is the Pet Shop Management System developed by itsourcecode, version 1.0. The vulnerability resides in an undefined function within admin_reject_completed.php. No additional sub‑versions are listed; applications built from this baseline remain susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit this flaw remotely by supplying malicious ID values through an exposed URL or form. Because the flaw directly interprets user input into a SQL statement, the likelihood of successful exploitation is high if the application does not sanitize the parameter. The impact, if successful, includes data exposure and potential data modification.

Generated by OpenCVE AI on October 2, 2026 at 02:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy a patched or newer version of the Pet Shop Management System if one is available.
  • If an update is not available, modify admin_reject_completed.php to validate that the ID parameter contains only numeric characters or to use a prepared statement with bound parameters.
  • Restrict access to the admin_reject_completed.php endpoint to authenticated administrators only, and enforce role‑based access control.
  • Implement logging of failed or suspicious SQL queries to detect potential exploitation attempts.

Generated by OpenCVE AI on October 2, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Title itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
First Time appeared Itsourcecode
Itsourcecode pet Shop Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode pet Shop Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Pet Shop Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T01:00:15.385Z

Reserved: 2026-10-01T17:55:45.907Z

Link: CVE-2026-104052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T02:17:01.327

Modified: 2026-10-02T02:17:01.327

Link: CVE-2026-104052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T02:30:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')