Description
A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2025-11-17: | Advisory disclosed |
| 2025-11-17: | VulDB entry created |
| 2025-11-17: | VulDB entry last update |
Credits
Labi (VulDB User)
References
vuldb.com/?id.332643 (VDB-332643 | code-projects Courier Management System add-new-officer.php sql injection)
vuldb.com/?ctiid.332643 (VDB-332643 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.691791 (Submit #691791 | code-projects Courier Management System V1.0 SQL Injection)
github.com/labi1106/cve/issues/1
code-projects.org/