CVE-2023-49544
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.9epss 0.7%
probabilidad de explotación
0.7%top 47% de las CVE
explotación observada
noninguna fuente lo reporta
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Productos afectados
n/a · n/aReferencias
https://github.com/geraldoalcantara/CVE-2023-49544https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusionhttps://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html