Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-13498: yashpokharna2555 Restaurant Management System: Remote Password Reset Risk

CVE-2026-13498
Summary

An attacker can exploit a weakness in the password reset feature of the yashpokharna2555 Restaurant Management System, potentially allowing them to access sensitive data. This vulnerability can be exploited remotely, and an exploit is available. The developers have been notified, but they have not yet addressed the issue.

Original title
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manip...
Original description
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
nvd CVSS2.0 7.5
nvd CVSS3.1 7.3
nvd CVSS4.0 5.5
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026