SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.
The ID parameter passed to the admin/view_customer.php script is not properly validated or sanitized before being used in an SQL query. An attacker can inject malicious SQL code directly through the URL parameter, allowing manipulation of the logic of queries directed to the database. The attack requires no authentication or user interaction and can be carried out remotely over the network.
An attacker can gain unauthorized access to data stored in the database (confidentiality) and modify or delete data (integrity). Depending on the database server configuration, it may also be possible to read sensitive system data or customer data.
Apply patches available from the vendor according to the references. As an interim measure, it is recommended to restrict access to the administrative panel only to trusted IP addresses and to implement validation and parameterization of SQL queries on the application side.
SourceCodester Pet Grooming Management Software version 1.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LMayurik Pet Grooming Management Software
APPMayurik1.0
Related vulnerabilities
A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting ...
The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Manage...
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/prof...
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Custom...
A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue ...