PT-2023-31435 · Unknown · Customer Support System
Geraldo Alcântara
·
Published
2023-12-20
·
Updated
2025-03-28
·
CVE-2023-49977
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Customer Support System version v1
Description
A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the
address parameter at "/customer support/index.php?page=new customer".Recommendations
For Customer Support System version v1, consider restricting access to the "/customer support/index.php?page=new customer" endpoint until a patch is available. As a temporary workaround, avoid using the
address parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Customer Support System