Itsourcecode · Best Courier Management System · CVE-2026-16229
**Name of the Vulnerable Software and Affected Versions**
itsourcecode Courier Management System versions prior to 1.1
**Description**
A flaw in the `/index.php` endpoint allows remote attackers to perform cross-site scripting (XSS) by manipulating the `page` argument. Cross-site scripting is a technique where malicious scripts are injected into trusted websites.
**Recommendations**
Update itsourcecode Courier Management System to a version newer than 1.0.
As a temporary workaround, restrict access to the `/index.php` endpoint or sanitize the `page` argument to prevent script injection.