PT-2025-35444 · Unknown+1 · Sourcecodester+1

M00N_L33

·

Published

2025-09-01

·

Updated

2025-09-08

·

CVE-2025-9759

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Campcodes/SourceCodester Courier Management System version 1.0
Description A security flaw has been discovered in the Signup function of the /ajax.php file, which results in SQL injection. Manipulation of the lastname argument can initiate the attack remotely. The exploit has been released to the public and may be exploited.
Recommendations As a temporary workaround, consider restricting access to the /ajax.php file until a patch is available.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-9759

Affected Products

Best Courier Management System
Sourcecodester