A vulnerability was found in SourceCodester Simple Cafe Billing System 1.0. It has been declared as critical. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection.

This vulnerability is tracked as CVE-2025-9701. The attack can be launched remotely. Moreover, an exploit is present.