Impact
SourceCodester’s Pet Grooming Management Software 1.0 contains a flaw in the Financial Report page that allows improper authorization, as described in the CVE. The vulnerability enables remote exploitation, with publicly available exploit code that might be used. However, the CVE data do not explicitly state whether authentication is required to access the vulnerable endpoint; based on the description, it is inferred that any user who can reach the endpoint may retrieve financial information, but this inference is not directly supported by the source.
Affected Systems
This vulnerability is specific to SourceCodester’s Pet Grooming Management Software. The affected version is 1.0, as listed in the CVE data. No additional products or revisions are known to be impacted.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, but the EPSS score of less than 1% reflects a low current likelihood of exploitation. Because the flaw can be exploited remotely and an attack path exists through the web application, the risk to an organization remains significant if the software is exposed to the internet. The vulnerability is not currently listed in the CISA KEV catalogue, yet the public availability of an exploit describes an active threat. Immediate action to patch or mitigate the authorization controls is recommended.
OpenCVE Enrichment