CVE-2025-9757

A vulnerability was determined in Campcodes/SourceCodester Courier Management System 1.0. Affected is the function Login of the file /ajax.php. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
References
Link Resource
https://github.com/lrjbsyh/CVE_Hunter/issues/8#issue-3348441601 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.322058 Permissions Required VDB Entry
https://vuldb.com/?id.322058 Third Party Advisory VDB Entry
https://vuldb.com/?submit.640675 Third Party Advisory VDB Entry
https://vuldb.com/?submit.640811 Third Party Advisory VDB Entry
https://github.com/lrjbsyh/CVE_Hunter/issues/8#issue-3348441601 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:campcodes:courier_management_system:1.0:*:*:*:*:*:*:*

History

08 Sep 2025, 13:54

Type Values Removed Values Added
References () https://github.com/lrjbsyh/CVE_Hunter/issues/8#issue-3348441601 - () https://github.com/lrjbsyh/CVE_Hunter/issues/8#issue-3348441601 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.322058 - () https://vuldb.com/?ctiid.322058 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.322058 - () https://vuldb.com/?id.322058 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.640675 - () https://vuldb.com/?submit.640675 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.640811 - () https://vuldb.com/?submit.640811 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:campcodes:courier_management_system:1.0:*:*:*:*:*:*:*
First Time Campcodes courier Management System
Campcodes

02 Sep 2025, 16:15

Type Values Removed Values Added
References () https://github.com/lrjbsyh/CVE_Hunter/issues/8#issue-3348441601 - () https://github.com/lrjbsyh/CVE_Hunter/issues/8#issue-3348441601 -

01 Sep 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-01 03:15

Updated : 2025-09-08 13:54


NVD link : CVE-2025-9757

Mitre link : CVE-2025-9757

CVE.ORG link : CVE-2025-9757


JSON object : View

Products Affected

campcodes

  • courier_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')