Vulnerability Details CVE-2025-9660
                A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.0
                        
                    
                    
                        
                            EPSS Ranking 10.5%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 7.3
                        
                    
                    
                        
                            CVSS v2 Score 7.5
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2025-9660
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:janobe:bakeshop_online_ordering_system:1.0