Impact
The vulnerability is located in the add_user.php component of SourceCodester Pet Grooming Management Software 1.0 and allows an attacker to manipulate the user creation process, potentially resulting in improper authorization within the application. The CVE description specifies that executing a manipulation can lead to improper authorization, allowing unauthorized actions in the system.
Affected Systems
The affected system is SourceCodester Pet Grooming Management Software version 1.0. No other versions or components are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is reported to be less than 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The description states that the attack may be launched remotely, implying that a remote attacker can send a crafted request to the add_user.php endpoint if it is reachable. Although the exploit has been publicly disclosed, no official patch or workaround is available, which limits available remediation options.
OpenCVE Enrichment