PT-2024-20387 · Unknown · Best Courier Management System

Published

2024-03-28

·

Updated

2025-05-02

·

CVE-2024-24407

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Best Courier management system version 1.0
Description The issue allows a remote attacker to obtain sensitive information via the print pdets.php component. This is due to a SQL Injection vulnerability. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Best Courier management system version 1.0, review the code for input sanitization and implement parameterized queries as soon as possible to mitigate the risk of SQL injection attacks. Consider temporarily disabling or restricting access to the print pdets.php component until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-24407

Affected Products

Best Courier Management System