PT-2026-35340 · Itsourcecode · Best Courier Management System

Willchen

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7077

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /edit parcel.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7077

Affected Products

Best Courier Management System