CVE-2026-7612: itsourcecode Courier Management System edit_user.php sql injection
A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7612?
CVE-2026-7612 is considered a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-7612?
To fix CVE-2026-7612, sanitize and validate all user inputs, particularly the ID parameter in the edit_user.php file.
What systems are affected by CVE-2026-7612?
CVE-2026-7612 affects version 1.0 of the itsourcecode Courier Management System.
What type of attack can CVE-2026-7612 facilitate?
CVE-2026-7612 can facilitate SQL injection attacks, allowing attackers to manipulate database queries.
Is CVE-2026-7612 exploitable remotely?
Yes, CVE-2026-7612 is exploitable remotely if the attacker can access the edit_user.php file.