PT-2026-43435 · Itsourcecode · Best Courier Management System

Ziran

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-9607

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9607

Affected Products

Best Courier Management System