NA

CVE-2023-49544

Published: 01/03/2024 Updated: 01/03/2024

Vulnerability Summary

A local file inclusion (LFI) in Customer Support System v1 allows malicious users to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.

Github Repositories

Customer Support System 1.0 - Local File Inclusion

CVE-2023-49544 Customer Support System 10 - Local File Inclusion Description: Customer Support System 10 is vulnerable to Local File Inclusion An authenticated user has the capability to access and read PHP files from the operating system by exploiting a Local File Inclusion (LFI) vulnerability through the wrapper filter Vulnerable Product Version: Custome