geraldoalcantara/CVE-2023-49548

geraldoalcantara/CVE-2023-49548

Releases0
Customer Support System 1.0 - SQL Injection Vulnerability in the "lastname" Parameter During "save_user" Operation

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.