Sceawere
Vulnerability Detail
CVE-2026-104053UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Pet Shop Management System
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 21h ago
- Vendor
- itsourcecode
- Product
- Pet Shop Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-02T02:17:01.560Z",
"pubdate": "2026-10-02T02:17:01.560Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the itsourcecode Pet Shop Management System 1.0. The vulnerability resides in the admin_reservefilter.php file and is triggered via improper sanitization of the 'filter' parameter.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries, leading to unauthorized data access, modification, or potential administrative compromise of the underlying database.\nThe vulnerability is characterized by the lack of input validation on user-supplied parameters, enabling the injection of arbitrary SQL commands.\nPublicly available exploit code increases the risk, as the barrier to entry for potential attackers is significantly lowered. Given the nature of SQL injection, this could result in complete database exposure or the bypass of authentication mechanisms.\nOrganizations using this software should treat this as a high-severity threat, as remote attackers can execute malicious payloads without prior authentication to the application's backend.",
"technicalDetails": "The root cause of this vulnerability is improper neutralization of special elements used in an SQL command within the 'admin_reservefilter.php' component. Specifically, the 'filter' argument is processed by the application without adequate input validation or the use of parameterized queries (prepared statements).\nAn attacker can exploit this by injecting crafted SQL sequences into the 'filter' parameter sent to the server. When the application processes this input, the database interpreter treats the injected malicious SQL as part of the intended query, rather than literal data. This allows for the alteration of the query's logic, enabling unauthorized retrieval, modification, or deletion of database contents.\nThe attack flow begins with a remote request sent to 'admin_reservefilter.php'. An attacker appends a malicious SQL payload to the 'filter' query parameter. Because the application logic fails to employ prepared statements or utilize sanitization libraries, the database engine executes the injected commands. For instance, an attacker could utilize UNION-based SQL injection to append results from sensitive system tables to the legitimate output or use boolean-based inference to map out database schemas.\nThe vulnerability is remotely exploitable, requiring no specific privileges on the system, which elevates the threat level significantly. Since the exploit is publicly available, the attack surface is exposed to automated scanning tools and malicious actors looking to harvest sensitive credentials or customer information stored within the Pet Shop Management System database.\nPost-exploitation impact includes, but is not limited to, unauthorized access to user accounts, sensitive pet or transaction data, and potential application-level administrative takeover. Depending on the database configuration and service account permissions, an attacker might also gain sufficient control to execute administrative functions or, in some environments, read or write files to the underlying filesystem."
}