Aller au contenu

Fiche vulnérabilité

CVE-2025-9757 : faille élevée Campcodes Courier Management System (CVSS 7.3)

Description

A vulnerability was determined in Campcodes/SourceCodester Courier Management System 1.0. Affected is the function Login of the file /ajax.php. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

En bref

Sévérité
Élevée (CVSS 7.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Exploitation active
Non signalée par la CISA
Publication
1 sept. 2025
Dernière mise à jour
2 sept. 2025

Produits concernés

  • Campcodes Courier Management System
  • SourceCodester Courier Management System

Références

Rechercher une autre vulnérabilité dans la base CVE