A vulnerability classified as critical was found in SourceCodester Pet Grooming Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services results in sql injection.
This vulnerability is reported as CVE-2025-10429. The attack can be launched remotely. Moreover, an exploit is present.