Description
A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used.
Published: 2026-04-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized user deletion via improper access control
Action: Patch immediately
AI Analysis

Impact

The vulnerability resides in the file /ajax.php?action=delete_user of the Best Courier Management System. By manipulating the ID parameter, an attacker can bypass authorization checks and delete arbitrary user accounts. This results in loss of user data and integrity violations, and may facilitate further attacks by removing legitimate users. The weakness corresponds to improper authorization and access control.

Affected Systems

The affected product is the SourceCodester and mayuri_k Best Courier Management System version 1.0. All deployments that include the /ajax.php User Delete Handler are vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while EPSS data is not available and the vulnerability is not listed in the KEV catalog. The exploit can be carried out remotely by sending crafted HTTP requests to the delete endpoint, so the attack vector is likely network-based. The public exploit confirms that remote attackers can achieve unauthorized deletion without needing additional credentials.

Generated by OpenCVE AI on April 2, 2026 at 15:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade the system to a version that fixes the delete_user access control flaw.
  • If a patch is not available immediately, restrict access to the /ajax.php?action=delete_user endpoint to administrative users only.
  • Implement additional authentication checks before performing user deletions.
  • Monitor application logs for unexpected delete_user requests and investigate anomalies.

Generated by OpenCVE AI on April 2, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mayuri K
Mayuri K best Courier Management System
Sourcecodester
Sourcecodester courier Management System
Vendors & Products Mayuri K
Mayuri K best Courier Management System
Sourcecodester
Sourcecodester courier Management System

Thu, 02 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used.
Title SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mayuri K Best Courier Management System
Sourcecodester Courier Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-02T14:19:51.165Z

Reserved: 2026-04-01T13:47:29.145Z

Link: CVE-2026-5330

cve-icon Vulnrichment

Updated: 2026-04-02T14:19:44.262Z

cve-icon NVD

Status : Deferred

Published: 2026-04-02T13:16:27.633

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:21:19Z

Weaknesses