CVE-2025-60783
MEDIUMCVSS 6.5/10EPSS 0.24%
Last modified
CVE-2025-60783 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through specially crafted SQL query strings.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through specially crafted SQL query strings.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rajvi-Patel-22 | Restaurant-Management-System-Dbms-Project | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-60783?
There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through specially crafted SQL query strings.
How severe is CVE-2025-60783?
CVE-2025-60783 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2025-60783?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6076Partner Software's Partner Software application and Partner …8.8
- CVE-2025-6077Partner Software's Partner Software Product and correspondin…9.8
- CVE-2025-60772Improper authentication in the web-based management interfac…9.8
- CVE-2025-6078Partner Software's Partner Software application and Partner …5.4
- CVE-2025-60781PHP Education Manager v1.0 is vulnerable to Cross Site Scrip…6.1
- CVE-2025-60782PHP Education Manager v1.0 is vulnerable to Cross Site Scrip…5.4
- CVE-2025-60784A vulnerability in the XiaozhangBang Voluntary Like System V…6.5
- CVE-2025-60785A remote code execution (RCE) vulnerability in the Postgres …8.8
- CVE-2025-60786A Zip Slip vulnerability in the import a Project component o…8.8
- CVE-2025-60787MotionEye v0.43.1b4 and before is vulnerable to OS Command I…7.2
- CVE-2025-6079The School Management System for Wordpress plugin for WordPr…8.8
- CVE-2025-60790ProcessWire CMS 3.0.246 allows a low-privileged user with la…6.5
Are you affected by CVE-2025-60783?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
