CVE-2023-49977: XSS
Published Mar 6, 2024
·Updated
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customersupport/index.php?page=newcustomer.
Affected Software
2 affected components
Customer Support System Customer Support System
oretnom23 Customer Support System=1.0
Event History
Mar 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49977?
CVE-2023-49977 has a high severity level due to its potential for cross-site scripting exploitation.
2
How do I fix CVE-2023-49977?
To fix CVE-2023-49977, validate and sanitize all user inputs, particularly the address parameter in the affected script.
3
Which version of Customer Support System is affected by CVE-2023-49977?
CVE-2023-49977 affects Customer Support System v1.
4
What type of vulnerability is CVE-2023-49977?
CVE-2023-49977 is a cross-site scripting (XSS) vulnerability.
5
Where can CVE-2023-49977 be exploited?
CVE-2023-49977 can be exploited via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.