Description
A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Published: 2026-03-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Authorization exposing sensitive financial data
Action: Apply Patch
AI Analysis

Impact

SourceCodester’s Pet Grooming Management Software 1.0 contains a flaw in the Financial Report page that allows improper authorization, as described in the CVE. The vulnerability enables remote exploitation, with publicly available exploit code that might be used. However, the CVE data do not explicitly state whether authentication is required to access the vulnerable endpoint; based on the description, it is inferred that any user who can reach the endpoint may retrieve financial information, but this inference is not directly supported by the source.

Affected Systems

This vulnerability is specific to SourceCodester’s Pet Grooming Management Software. The affected version is 1.0, as listed in the CVE data. No additional products or revisions are known to be impacted.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, but the EPSS score of less than 1% reflects a low current likelihood of exploitation. Because the flaw can be exploited remotely and an attack path exists through the web application, the risk to an organization remains significant if the software is exposed to the internet. The vulnerability is not currently listed in the CISA KEV catalogue, yet the public availability of an exploit describes an active threat. Immediate action to patch or mitigate the authorization controls is recommended.

Generated by OpenCVE AI on April 16, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SourceCodester Pet Grooming Management Software to a patched version that includes proper authorization controls for the Financial Report page.
  • If a patch is unavailable, restrict access to the Financial Report page by implementing application‑level access controls or disabling the feature for non‑privileged users.
  • Configure the web server or firewall to limit traffic to the application from trusted networks only, blocking external access to the Financial Report endpoint.

Generated by OpenCVE AI on April 16, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 12 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mayurik
Mayurik pet Grooming Management Software
CPEs cpe:2.3:a:mayurik:pet_grooming_management_software:1.0:*:*:*:*:*:*:*
Vendors & Products Mayurik
Mayurik pet Grooming Management Software

Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester pet Grooming Management Software
Vendors & Products Sourcecodester
Sourcecodester pet Grooming Management Software

Sun, 08 Mar 2026 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Title SourceCodester Pet Grooming Management Software Financial Report improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mayurik Pet Grooming Management Software
Sourcecodester Pet Grooming Management Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-12T14:59:38.533Z

Reserved: 2026-03-07T18:11:09.978Z

Link: CVE-2026-3738

cve-icon Vulnrichment

Updated: 2026-03-12T14:59:35.300Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-08T14:15:54.753

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T10:45:26Z

Weaknesses