Vulnerabilities (CVE)

Filtered by vendor Mayurik Subscribe
Filtered by product Best Courier Management System
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6300 1 Mayurik 1 Best Courier Management System 2023-11-30 N/A 6.1 MEDIUM
A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function. The manipulation of the argument page with the input </TiTlE><ScRiPt>alert(1)</ScRiPt> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246126 is the identifier assigned to this vulnerability.
CVE-2023-6301 1 Mayurik 1 Best Courier Management System 2023-11-30 N/A 6.1 MEDIUM
A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id with the input </TiTlE><ScRiPt>alert(1)</ScRiPt> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246127.
CVE-2023-46980 1 Mayurik 1 Best Courier Management System 2023-11-14 N/A 9.8 CRITICAL
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.