Executive brief
SourceCodester Pet Grooming Management Software is a web-based tool for managing pet grooming services. A SQL injection vulnerability in the barcode lookup feature allows attackers to remotely manipulate database queries without authentication, potentially exposing customer data, service records, pricing information, or enabling unauthorized modifications to the system's operational data.
Technical details
A blind SQL injection vulnerability exists in the get_barcode_data.php file's barcode parameter. The vulnerable code constructs SQL queries using unsanitized user input directly: SELECT product_id FROM tbl_barcode WHERE barcode = '$barcode', without prepared statements or input validation. An attacker can inject malicious SQL via the barcode POST parameter to extract database contents, modify or delete records, or execute arbitrary database operations. No authentication is required to reach the vulnerable endpoint. Exploitation has been confirmed with automated tools and proofs-of-concept are publicly available.
Affected products
- SourceCodester Pet Grooming Management Software 1.0
Timeline
- 2026-07-01: disclosed: Vulnerability reported on GitHub
- 2026-08-17: advisory: CVE-2026-75014 published