A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName leads to sql injection.

This vulnerability is uniquely identified as CVE-2025-12316. The attack is possible to be carried out remotely. Moreover, an exploit is present.