Product
oretnom23 customer support system
20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-70141
CVE-2025-40729
CVE-2025-40728
CVE-2023-49978
CVE-2023-51281
CVE-2023-49977
CVE-2023-49976
CVE-2023-49974
CVE-2023-49973
CVE-2023-49971
CVE-2023-49970
CVE-2023-49969
CVE-2023-49968
CVE-2023-49548
CVE-2023-49547
CVE-2023-49546
CVE-2023-49545
CVE-2023-49544
CVE-2023-50071
CVE-2023-50070
all versions
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher doe
all versions
Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers
all versions
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, crea
all versions
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute a
all versions
Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted
all versions
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML
all versions
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML
all versions
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML
all versions
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML
all versions
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML
all versions
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/
all versions
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index
all versions
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manag
all versions
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support
all versions
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support
all versions
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/aj
all versions
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within th
all versions
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized ac
all versions
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_de
all versions
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ti