CVE-2023-49545: High severity customer support system vulnerability
Published Mar 1, 2024
·Updated
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
Affected Software
2 affected components
Customer Support System Customer Support System
oretnom23 Customer Support System=1.0
Event History
Mar 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49545?
CVE-2023-49545 is considered a medium-severity vulnerability that allows unauthorized directory listing.
2
How do I fix CVE-2023-49545?
To fix CVE-2023-49545, implement proper access controls to restrict unauthorized directory listing in the application.
3
What kind of information can be exposed due to CVE-2023-49545?
CVE-2023-49545 can expose sensitive directories and files within the Customer Support System application.
4
Is authentication bypass possible with CVE-2023-49545?
Yes, CVE-2023-49545 permits attackers to list directories and files without any authentication.
5
What applications are affected by CVE-2023-49545?
CVE-2023-49545 affects the Customer Support System version 1 and possibly other versions if not patched.