Unknown · Best Courier Management System · CVE-2020-35327
Name of the Vulnerable Software and Affected Versions:
Courier Management System version 1.0
Description:
A SQL injection issue was found, which can be exploited through the `ref no` parameter in a POST request to the "admin class.php" endpoint. This allows for potential unauthorized access and manipulation of data.
Recommendations:
For Courier Management System version 1.0, as a temporary workaround, consider restricting access to the "admin class.php" endpoint or disabling the use of the `ref no` parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.