PT-2023-19729 · Unknown · Simple Customer Relationship Management System

Kap0K

·

Published

2023-02-27

·

Updated

2023-03-01

·

CVE-2023-24656

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Customer Relationship Management System version 1.0
Description The issue is related to a SQL injection vulnerability. This vulnerability can be exploited via the subject parameter under the Create Ticket function.
Recommendations For Simple Customer Relationship Management System version 1.0, avoid using the subject parameter in the Create Ticket function until the issue is resolved. As a temporary workaround, consider restricting access to the Create Ticket function to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-24656

Affected Products

Simple Customer Relationship Management System