PT-2025-37451 · Sourcecodester · Pet Grooming Management

Joinia

·

Published

2025-09-15

·

Updated

2025-09-18

·

CVE-2025-10428

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Pet Grooming Management Software version 1.0
Description A security issue exists in SourceCodester Pet Grooming Management Software 1.0. The vulnerability is due to unrestricted upload capabilities resulting from the manipulation of the website image argument within an unknown function of the /admin/seo setting.php file, part of the Setting Handler component. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations As a temporary workaround, restrict access to the /admin/seo setting.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10428

Affected Products

Pet Grooming Management