CVE-2023-49974: XSS
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customersupport/index.php?page=customerlist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49974?
CVE-2023-49974 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2023-49974?
To fix CVE-2023-49974, ensure proper input validation and output encoding to mitigate the risk of XSS attacks.
What kind of attacks can exploit CVE-2023-49974?
CVE-2023-49974 can be exploited to execute arbitrary web scripts or HTML, leading to unauthorized actions on behalf of users.
Which component of the Customer Support System is affected by CVE-2023-49974?
CVE-2023-49974 affects the contact parameter at /customer_support/index.php?page=customer_list.
Who is impacted by CVE-2023-49974?
Users of Customer Support System v1 are impacted by the vulnerability, as attackers can execute malicious scripts.