CVE-2023-50071
HIGHSourcecodester Customer Support System 1.0 - SQL Injection via Department ID or Name Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-50071. PoCs published by Geraldo Alcantara, geraldoalcantara.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Customer Support System 1.0 via the `subject` parameter in a POST request to `/ajax.php?action=save_ticket`. The payload uses a time-based blind SQLi technique with `sleep(5)` to confirm vulnerability.
Description
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Customer Support System 1.0 via the `subject` parameter in a POST request to `/ajax.php?action=save_ticket`. The payload uses a time-based blind SQLi technique with `sleep(5)` to confirm vulnerability.
The repository provides a detailed technical analysis of CVE-2023-50071, a SQL injection vulnerability in Customer Support System 1.0. It includes specific payloads, HTTP request examples, and steps to reproduce the vulnerability, demonstrating a clear understanding of the issue.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H