CRITICAL🇵🇱 Wersja polska

CVE-2025-60316

CVSS 9.4v3.1pub. 2025-10-09upd. 2025-10-16

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.

🤖 AI Analysis
How it works

The ID parameter passed to the admin/view_customer.php script is not properly validated or sanitized before being used in an SQL query. An attacker can inject malicious SQL code directly through the URL parameter, allowing manipulation of the logic of queries directed to the database. The attack requires no authentication or user interaction and can be carried out remotely over the network.

Impact

An attacker can gain unauthorized access to data stored in the database (confidentiality) and modify or delete data (integrity). Depending on the database server configuration, it may also be possible to read sensitive system data or customer data.

Mitigation & patch

Apply patches available from the vendor according to the references. As an interim measure, it is recommended to restrict access to the administrative panel only to trusted IP addresses and to implement validation and parameterization of SQL queries on the application side.

Who is affected

SourceCodester Pet Grooming Management Software version 1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
  • Mayurik Pet Grooming Management Software

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-63298HIGH8.2same product

A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting ...

CVE-2025-63717MEDIUM6.5same product

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Manage...

CVE-2025-60318MEDIUM6.1same product

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/prof...

CVE-2025-61087MEDIUM6.1same product

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Custom...

CVE-2025-11057MEDIUM5.5same product

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue ...