Description
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL injection via admin_reservefilter.php
Action: Patch
AI Analysis

Impact

A remote attacker can manipulate the filter argument in admin_reservefilter.php to inject SQL code, enabling extraction or modification of the database. The vulnerability is an uncontrolled input that is directly incorporated into a SQL query, potentially allowing unauthorized data access or alteration.

Affected Systems

itsourcecode Pet Shop Management System version 1.0 is affected. The issue resides in the admin_reservefilter.php file and does not appear limited to a specific submodule or configuration.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. An exploit is publicly available, but the EPSS score is not disclosed. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the injection remotely over HTTP by sending crafted requests to the filtered endpoint, and because the database driver likely uses plain queries, the attack vector is effectively remote network access to the web application.

Generated by OpenCVE AI on October 2, 2026 at 02:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Pet Shop Management System to any version that fixes the SQL injection in admin_reservefilter.php.
  • If no patch is available, modify the code to use prepared statements or properly escaped input for the filter parameter.
  • Reduce database user privileges associated with the application to the minimum required functions.

Generated by OpenCVE AI on October 2, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Title itsourcecode Pet Shop Management System admin_reservefilter.php sql injection
First Time appeared Itsourcecode
Itsourcecode pet Shop Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode pet Shop Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Pet Shop Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T01:15:16.482Z

Reserved: 2026-10-01T17:55:51.198Z

Link: CVE-2026-104053

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T02:17:01.560

Modified: 2026-10-02T02:17:01.560

Link: CVE-2026-104053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T03:00:15Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')