A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-06T00:00:00
Updated: 2024-11-01T15:26:10.264Z
Reserved: 2023-12-04T00:00:00
Link: CVE-2023-49973
Vulnrichment
Updated: 2024-08-02T22:09:49.635Z
NVD
Status : Awaiting Analysis
Published: 2024-03-06T01:15:07.063
Modified: 2024-11-01T16:35:04.683
Link: CVE-2023-49973
Redhat
No data.