6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-9660
Source
VulDB
Published
Aug 29, 2025 at 16:32
Modified
Aug 29, 2025 at 16:59
Affected Product
Vendor
SourceCodester
Product
Bakeshop Online Ordering System
Version
1.0
Affected Versions
SourceCodester Bakeshop Online Ordering System 1.0