What is CVE-2026-75014?
A critical SQL injection vulnerability has been identified in SourceCodester Pet Grooming Management Software 1.0. The flaw in the `/admin/get_barcode_data.php` file allows remote exploitation via the improperly sanitized `barcode` argument. It is advised to immediately restrict public access to the affected management software until an official patch is released by the vendor.
Azərbaycanca: SourceCodester Pet Grooming Management Software 1.0-da kritik SQL injection zəifliyi aşkarlanıb. Bu, `/admin/get_barcode_data.php` faylındakı `barcode` parametrinin düzgün yoxlanılmaması səbəbindən uzaqdan hücum təşkil etməyə imkan verir. Təhlükəsizliyiniz üçün dərhal istehsalçı tərəfindən rəsmi patch təmin olunana qədər təsirlənmiş idarəetmə proqramının internetə açıq girişini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
What is the cause of the critical vulnerability (CVE-2026-75014) found in SourceCodester Pet Grooming Management Software?
The vulnerability is an SQL injection caused by improper sanitization of the `barcode` parameter in the `/admin/get_barcode_data.php` file.
What temporary measure should be taken until an official patch for CVE-2026-75014 is available?
It is advised to immediately restrict public access to the affected management software until an official patch is released by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.