A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected by this issue is some unknown functionality of the file /add_dealerrequest.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}

epss

{'score': 0.00031}


Tue, 15 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared 1000projects
1000projects abc Courier Management System
CPEs cpe:2.3:a:1000projects:abc_courier_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products 1000projects
1000projects abc Courier Management System

Mon, 14 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}


Sat, 12 Jul 2025 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected by this issue is some unknown functionality of the file /add_dealerrequest.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Title 1000projects ABC Courier Management add_dealerrequest.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-07-12T08:02:05.310Z

Updated: 2025-07-14T20:12:20.601Z

Reserved: 2025-07-11T11:56:49.969Z

Link: CVE-2025-7466

cve-icon Vulnrichment

Updated: 2025-07-14T20:08:22.634Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-12T08:15:24.440

Modified: 2025-07-15T18:08:53.070

Link: CVE-2025-7466

cve-icon Redhat

No data.