CVE-2025-13396: code-projects Courier Management System add-office.php sql injection
A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13396?
CVE-2025-13396 has been classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-13396?
To fix CVE-2025-13396, ensure input validation and parameterized queries are implemented in the /add-office.php file to prevent SQL injection.
What systems are affected by CVE-2025-13396?
CVE-2025-13396 affects version 1.0 of the Code-projects Courier Management System.
Can CVE-2025-13396 be exploited remotely?
Yes, CVE-2025-13396 can be exploited remotely, allowing attackers to execute SQL injection attacks.
What type of attack is associated with CVE-2025-13396?
CVE-2025-13396 is associated with SQL Injection attacks targeting the OfficeName argument in the /add-office.php file.