CVE-2026-10254
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.33%
- CWE
- CWE-538, CWE-200
- Published
- 2026-06-01
- Last modified
- 2026-06-01
Affected products
- SourceCodester Pet Grooming Management Software
Weakness type
Related vulnerabilities
- CVE-2026-80175 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-69507 — Microsoft Windows Search Component Information Disclosure Vulnerability
- CVE-2026-67361 — Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
- CVE-2026-19229 — SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
- CVE-2026-12762 — Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
- CVE-2026-15574 — Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default
- CVE-2025-36372 — IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
- CVE-2026-50099 — Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directory