Executive brief
A security vulnerability exists in the itsourcecode Courier Management System, a web application used for managing delivery and logistics operations. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login session information, unauthorized actions on behalf of the user, or redirection to fraudulent websites.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in itsourcecode Courier Management System version 1.0. The flaw is located in the /index.php component, where the 'page' URL parameter is reflected into the page output without sufficient sanitization or encoding. A remote, unauthenticated attacker can exploit this by persuading a victim to visit a specially crafted URL containing a malicious JavaScript payload. Successful exploitation allows for the execution of arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking (cookie theft), unauthorized data access, or DOM manipulation. The vulnerability is confirmed by public exploit documentation demonstrating the use of <script> tags in the affected parameter.
Affected products
- itsourcecode Courier Management System 1.0
Timeline
- 2026-06-14: disclosed: Vulnerability report published on GitHub by saintpierrezgnk4950-pixel
- 2026-07-19: advisory: CVE-2026-16229 published by NVD/VulDB