Impact
A remote attacker can manipulate the filter argument in admin_reservefilter.php to inject SQL code, enabling extraction or modification of the database. The vulnerability is an uncontrolled input that is directly incorporated into a SQL query, potentially allowing unauthorized data access or alteration.
Affected Systems
itsourcecode Pet Shop Management System version 1.0 is affected. The issue resides in the admin_reservefilter.php file and does not appear limited to a specific submodule or configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. An exploit is publicly available, but the EPSS score is not disclosed. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the injection remotely over HTTP by sending crafted requests to the filtered endpoint, and because the database driver likely uses plain queries, the attack vector is effectively remote network access to the web application.
OpenCVE Enrichment