---
id: CVE-2026-104052
title: >-
  itsourcecode Pet Shop Management System admin_reject_completed.php sql
  injection
summary: >-
  A vulnerability was determined in itsourcecode Pet Shop Management System 1.0.
  The affected element is an unknown function of the file
  admin_reject_completed.php. This manipulation of the argument ID causes sql
  injection. It is possible …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'
cvssSource: cna
cwe:
  - CWE-89
  - CWE-74
vendor: itsourcecode
product: Pet Shop Management System
affected:
  - pet_shop_management_system 1.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T01:00:15.385Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-104052'
references:
  - url: 'https://vuldb.com/vuln/412760'
    label: >-
      VDB-412760 | itsourcecode Pet Shop Management System
      admin_reject_completed.php sql injection
  - url: 'https://vuldb.com/vuln/412760/cti'
    label: 'VDB-412760 | CTI Indicators (IOB, IOC, TTP, IOA)'
  - url: 'https://vuldb.com/cve/CVE-2026-104052'
    label: CVE-2026-104052 | CVE Analysis and Report
  - url: 'https://vuldb.com/submit/959310'
    label: >-
      Submit #959310 | itsourcecode Pet Shop Management System V1.0 SQL
      Injection
  - url: 'https://github.com/Useless-Noob-hub/cve/issues/1'
  - url: 'https://itsourcecode.com/'
tags:
  - cve.org
ingestedAt: '2026-10-02T02:07:09.203Z'
---

## Overview

A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

## Affected

- `pet_shop_management_system 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
