VendorsMayuri Kbest_courier_management_system1.0
Vulnerabilities

Mayuri K Best Courier Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2023-46980
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.
Published 2023-11-03 · Modified
9.8EPSS 0.015
CVE-2024-48581
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
Published 2024-10-25 · Analyzed
9.8EPSS 0.011
CVE-2024-48580
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.
Published 2024-10-25 · Analyzed
9.8EPSS 0.009
CVE-2024-4945
SourceCodester Best Courier Management System view_parcel.php unrestricted upload
Published 2024-05-16 · Analyzed
9.8EPSS 0.009
CVE-2023-46005
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.
Published 2023-10-18 · Modified
9.8EPSS 0.007
CVE-2023-46007
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.
Published 2023-10-18 · Modified
9.8EPSS 0.007
CVE-2023-46006
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.
Published 2023-10-18 · Modified
9.8EPSS 0.007
CVE-2023-6898
SourceCodester Best Courier Management System manage_user.php sql injection
Published 2023-12-17 · Modified
9.8EPSS 0.006
CVE-2023-5269
SourceCodester Best Courier Management System GET Parameter parcel_list.php sql injection
Published 2023-09-29 · Modified
8.8EPSS 0.006
CVE-2023-5270
SourceCodester Best Courier Management System view_parcel.php sql injection
Published 2023-09-29 · Analyzed
8.8EPSS 0.006
CVE-2023-5271
SourceCodester Best Courier Management System edit_parcel.php sql injection
Published 2023-09-29 · Analyzed
8.8EPSS 0.006
CVE-2023-5272
SourceCodester Best Courier Management System GET Parameter edit_parcel.php sql injection
Published 2023-09-29 · Analyzed
8.8EPSS 0.006
CVE-2023-46004
Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.
Published 2023-10-18 · Modified
7.2EPSS 0.007
CVE-2023-6300
SourceCodester Best Courier Management System cross site scripting
Published 2023-11-26 · Modified
6.1EPSS 0.006
CVE-2023-6301
SourceCodester Best Courier Management System GET Parameter parcel_list.php cross site scripting
Published 2023-11-26 · Modified
6.1EPSS 0.006
CVE-2023-5302
SourceCodester Best Courier Management System Manage Account Page cross site scripting
Published 2023-09-30 · Modified
5.4EPSS 0.006
CVE-2023-5273
SourceCodester Best Courier Management System manage_parcel_status.php cross site scripting
Published 2023-09-29 · Modified
5.4EPSS 0.005
CVE-2023-46451
Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
Published 2023-10-31 · Modified
5.4EPSS 0.004
CVE-2024-24407
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.
Published 2024-03-28 · Analyzed
5.3EPSS 0.006