Description
A vulnerability was identified in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /edit_parcel.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
willchen (VulDB User)
References
vuldb.com/vuln/359652 (VDB-359652 | itsourcecode Courier Management System edit_parcel.php sql injection)
vuldb.com/vuln/359652/cti (VDB-359652 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/799547 (Submit #799547 | itsourcecode Courier Management System V1.0 SQL Injection)
github.com/Beatriz-ai-boop/cve/issues/6
itsourcecode.com/