8.8
CVSSv3

CVE-2023-50070

Published: 29/12/2023 Updated: 05/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

Vulnerable Product Search on Vulmon Subscribe to Product

oretnom23 customer support system 1.0

Github Repositories

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket in Customer Support System 1.0 allow authenticated attackers to execute arbitrary SQL commands via department_id, customer_id and subject.

CVE-2023-50070 Customer Support System 10 - Multiple SQL injection vulnerabilities - save_ticket Description: Multiple SQL injection vulnerabilities in /customer_support/ajaxphp?action=save_ticket in Customer Support System 10 allow authenticated attackers to execute arbitrary SQL commands via department_id, customer_id and subject Vulnerable Product Version:&n