CVE-2025-40728: SQL injection vulnerability in Customer Support System
Published Jun 16, 2025
·Updated
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customersupport/manageuser.php endpoint.
Affected Software
2 affected components
Unknown Customer Support System
oretnom23 Customer Support System=1.0
Event History
Jun 16, 2025
CVE Published
via MITRE·08:29 AM
Data Sourced
via MITRE·08:29 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40728?
CVE-2025-40728 is classified as a critical severity SQL injection vulnerability.
2
How do I fix CVE-2025-40728?
To fix CVE-2025-40728, validate and sanitize the id parameter in the /customer_support/manage_user.php endpoint.
3
What can an attacker do with CVE-2025-40728?
An authenticated attacker can retrieve, create, update, and delete databases using the id parameter due to CVE-2025-40728.
4
Is CVE-2025-40728 present in all versions of Customer Support System?
CVE-2025-40728 affects Customer Support System v1.0 specifically.
5
What type of vulnerability is CVE-2025-40728?
CVE-2025-40728 is an SQL injection vulnerability.