PT-2024-14081 · Unknown · Customer Support System

Geraldo Alcântara

·

Published

2024-03-07

·

Updated

2025-03-28

·

CVE-2023-51281

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Customer Support System version 1.0
Description The issue allows a remote attacker to escalate privileges via a crafted script using parameters such as firstname, lastname, middlename, contact, and address.
Recommendations For Customer Support System version 1.0, consider disabling the use of the firstname, lastname, middlename, contact, and address parameters in scripts until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51281

Affected Products

Customer Support System