A vulnerability, which was classified as critical, has been found in Campcodes Courier Management System 1.0. Affected is the function
Login
of the file /ajax.php. This manipulation of the argument email causes sql injection.
This vulnerability is tracked as CVE-2025-9757. The attack is possible to be carried out remotely. Moreover, an exploit is present.