CVE-2025-13302

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
17/11/2025
Last modified:
18/11/2025

Description

A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.