PT-2026-43432 · Itsourcecode · Best Courier Management System

Zzl08

·

Published

2026-05-26

·

Updated

2026-05-27

·

CVE-2026-9606

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions itsourcecode Courier Management System version 1.0
Description A remote SQL injection exists in the /manage user.php file. This issue occurs when the ID argument is manipulated, allowing an attacker to execute arbitrary SQL commands on the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9606

Affected Products

Best Courier Management System