CVE-2023-49969
MEDIUMCustomer Support System v1 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-49969. PoCs published by geraldoalcantara.
AI-analyzed exploit summary This repository provides a functional SQL Injection (SQLi) proof-of-concept for CVE-2023-49969 in Customer Support System 1.0. The exploit manipulates the 'id' URL parameter in the edit_customer page to execute arbitrary SQL commands, demonstrated with a time-based payload.
Description
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
Exploits (1)
This repository provides a functional SQL Injection (SQLi) proof-of-concept for CVE-2023-49969 in Customer Support System 1.0. The exploit manipulates the 'id' URL parameter in the edit_customer page to execute arbitrary SQL commands, demonstrated with a time-based payload.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N