CVE-2026-104052: itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
Published Oct 2, 2026
·Updated
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file adminrejectcompleted.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
itsourcecode Pet Shop Management System=1.0
Event History
Oct 2, 2026
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that low privileges are required. The attack can be initiated remotely and does not require user interaction.
2
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
3
Which component should be prioritized for investigation?
Prioritize the admin_reject_completed.php endpoint and its handling of the ID argument. The reported flaw is SQL injection in an unknown function within that file.