CVE-2024-48581
- EPSS 2.14%
- Veröffentlicht 25.10.2024 16:15:10
- Zuletzt bearbeitet 06.05.2025 21:12:54
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
CVE-2024-48580
- EPSS 1.38%
- Veröffentlicht 25.10.2024 16:15:09
- Zuletzt bearbeitet 02.05.2025 19:51:54
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.
CVE-2024-4945
- EPSS 0.25%
- Veröffentlicht 16.05.2024 05:15:52
- Zuletzt bearbeitet 10.02.2025 13:34:57
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file view_parcel.php. The manipulation of the argument id leads to unrestricted upload. It i...
CVE-2024-24407
- EPSS 0.14%
- Veröffentlicht 28.03.2024 23:15:46
- Zuletzt bearbeitet 02.05.2025 19:51:07
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.
CVE-2023-6898
- EPSS 0.05%
- Veröffentlicht 17.12.2023 11:15:08
- Zuletzt bearbeitet 23.12.2024 15:18:44
A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. The exploit has been ...
CVE-2023-6301
- EPSS 0.17%
- Veröffentlicht 27.11.2023 00:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:34
A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file parcel_list.php of the component GET Parameter Handler. The mani...
CVE-2023-6300
- EPSS 0.17%
- Veröffentlicht 27.11.2023 00:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:34
A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function. The manipulation of the argument page with the input </TiTlE><ScRiPt>alert(1)</ScRiPt> leads to cro...
CVE-2023-46980
- EPSS 7.49%
- Veröffentlicht 03.11.2023 16:15:31
- Zuletzt bearbeitet 21.11.2024 08:29:35
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.
CVE-2023-46451
- EPSS 0.12%
- Veröffentlicht 31.10.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 08:28:32
Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
CVE-2023-46007
- EPSS 0.07%
- Veröffentlicht 18.10.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:27:44
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.