Impact
An injection flaw exists in the manage_user.php component of itsourcecode Courier Management System. The vulnerability is triggered by manipulating the ID argument, allowing an attacker to insert arbitrary SQL code into database queries. This weakness, classified as CWE-74 and CWE-89, can lead to unauthorized data disclosure, modification, or execution of arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the application’s underlying data.
Affected Systems
The flaw affects the Courier Management System version 1.0 developed by itsourcecode. No additional version constraints or sub‑product information are available from the incoming data.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity, and there is no EPSS score provided. It is not listed in the CISA KEV catalog. The remote nature of the attack, coupled with the lack of a publicly available patch, suggests that exploitation is feasible by any remote actor capable of sending crafted requests to the unprotected ID parameter.
OpenCVE Enrichment