PT-2025-37407 · Sourcecodester · Pet Grooming Management

Zhe0

·

Published

2025-09-14

·

Updated

2025-09-18

·

CVE-2025-10396

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Pet Grooming Management Software version 1.0
Description: A SQL injection issue exists in SourceCodester Pet Grooming Management Software version 1.0 due to manipulation of the ID argument in the /admin/edit role.php file. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations: As a temporary workaround, restrict access to the /admin/edit role.php file to minimize the risk of exploitation. Sanitize the ID parameter before using it in SQL queries.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10396

Affected Products

Pet Grooming Management