CVE-2023-49544
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
01/03/2024
Last modified:
28/03/2025
Description
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
Impact
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:oretnom23:customer_support_system:1.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/geraldoalcantara/CVE-2023-49544
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
- https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html
- https://github.com/geraldoalcantara/CVE-2023-49544
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
- https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html



