Impact
The vulnerability resides in the file /ajax.php?action=delete_user of the Best Courier Management System. By manipulating the ID parameter, an attacker can bypass authorization checks and delete arbitrary user accounts. This results in loss of user data and integrity violations, and may facilitate further attacks by removing legitimate users. The weakness corresponds to improper authorization and access control.
Affected Systems
The affected product is the SourceCodester and mayuri_k Best Courier Management System version 1.0. All deployments that include the /ajax.php User Delete Handler are vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while EPSS data is not available and the vulnerability is not listed in the KEV catalog. The exploit can be carried out remotely by sending crafted HTTP requests to the delete endpoint, so the attack vector is likely network-based. The public exploit confirms that remote attackers can achieve unauthorized deletion without needing additional credentials.
OpenCVE Enrichment