Threats Tagged 'cve-2025-11553'
View all threats tagged with 'cve-2025-11553'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-11553'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-11553 is a medium severity SQL injection vulnerability in code-projects Courier Management System version 1.0, specifically in the /add-courier.php file via the Shippername parameter. The vulnerability allows remote attackers to manipulate SQL queries without authentication or user interaction, potentially compromising confidentiality, integrity, and availability of the backend database. Although no public exploits are currently observed in the wild, proof-of-concept code is available, increasing the risk of exploitation. This threat primarily affects organizations using this specific courier management software, which may include logistics and delivery companies. European organizations relying on this system could face data breaches, unauthorized data manipulation, or service disruption. Mitigation requires immediate input validation, parameterized queries, and software updates or patches once available. Countries with significant logistics sectors and known usage of this software are at higher risk. Given the medium CVSS score and ease of remote exploitation without authentication, organizations should prioritize remediation to prevent potential attacks. Join the discussion | CVE Database V5 | 10/09/2025, 19:32:06 UTC Added: 10/09/2025, 19:37:57 UTC |
Showing 1 to 1 of 1 result