CVE-2023-49978: High severity customer support system vulnerability
Published Mar 6, 2024
·Updated
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.
Affected Software
2 affected components
Customer Support System Customer Support System
oretnom23 Customer Support System=1.0
Event History
Mar 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 21, 2024
Data Sourced
via NVD·02:49 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49978?
CVE-2023-49978 is classified as a critical vulnerability due to its impact on administrative access control.
2
How do I fix CVE-2023-49978?
To fix CVE-2023-49978, update the Customer Support System to a patched version that secures access controls for administrative pages.
3
What systems are affected by CVE-2023-49978?
CVE-2023-49978 affects the Customer Support System version 1.0.
4
What risks are associated with CVE-2023-49978?
CVE-2023-49978 presents risks of unauthorized access, allowing non-administrators to execute actions reserved for administrators.
5
Can CVE-2023-49978 lead to data breaches?
Yes, CVE-2023-49978 can lead to data breaches by exposing sensitive administrative functionalities to unauthorized users.