Description
A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-04-01: | Advisory disclosed |
| 2026-04-01: | VulDB entry created |
| 2026-04-01: | VulDB entry last update |
Credits
Zyyyy (VulDB User)
References
vuldb.com/vuln/354664 (VDB-354664 | SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control)
vuldb.com/vuln/354664/cti (VDB-354664 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/780734 (Submit #780734 | Mayuri K. Gaatitrack Courier Management System 1.0 Broken Access Control)
github.com/...lity-Report/tree/main/Gaatitrack-Unauth-Delete