Description
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-03-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper authorization
Action: Assess Impact
AI Analysis

Impact

The vulnerability is located in the add_user.php component of SourceCodester Pet Grooming Management Software 1.0 and allows an attacker to manipulate the user creation process, potentially resulting in improper authorization within the application. The CVE description specifies that executing a manipulation can lead to improper authorization, allowing unauthorized actions in the system.

Affected Systems

The affected system is SourceCodester Pet Grooming Management Software version 1.0. No other versions or components are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is reported to be less than 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The description states that the attack may be launched remotely, implying that a remote attacker can send a crafted request to the add_user.php endpoint if it is reachable. Although the exploit has been publicly disclosed, no official patch or workaround is available, which limits available remediation options.

Generated by OpenCVE AI on April 17, 2026 at 12:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether SourceCodester has released a patch or update that addresses the improper authorization issue in add_user.php; apply it promptly if available.
  • If no patch is available, restrict the add_user.php endpoint to authenticated users only or place it behind a firewall or internal network segment to limit external exposure.
  • Consider replacing the affected software with a newer version that does not contain the vulnerable component, if an upgrade path is supported.
  • Review and reinforce the application’s role‑based access controls to ensure that only authorized users can invoke user creation functions, and remediate any coding or configuration gaps identified.

Generated by OpenCVE AI on April 17, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mayurik
Mayurik pet Grooming Management Software
CPEs cpe:2.3:a:mayurik:pet_grooming_management_software:1.0:*:*:*:*:*:*:*
Vendors & Products Mayurik
Mayurik pet Grooming Management Software

Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester pet Grooming Management Software
Vendors & Products Sourcecodester
Sourcecodester pet Grooming Management Software

Sun, 08 Mar 2026 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Pet Grooming Management Software User Creation add_user.php improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mayurik Pet Grooming Management Software
Sourcecodester Pet Grooming Management Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-11T19:48:21.192Z

Reserved: 2026-03-07T18:11:05.163Z

Link: CVE-2026-3737

cve-icon Vulnrichment

Updated: 2026-03-11T19:46:43.444Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-08T14:15:54.503

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T12:15:18Z

Weaknesses