CVE-2026-5330

MEDIUM

SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control

Title source: cna

Description

A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (2)
mayuri_k/Best Courier Management System 1.0
SourceCodester/Best Courier Management System 1.0
Published Apr 02, 2026
Tracked Since Apr 02, 2026