← Vulnerability feed

Vulnerability record · CVE-2023-49548 · published 5 March 2024

CVE-2023-49548: Oretnom23 customer support system sql injection vulnerability

OOretnom23 · Customer Support System

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

8.8 CVSS 3.1 High EPSS 0.76% · top 46.7% CWE-89 · SQL injection
8.8CVSS 3.1 base score
0.76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49548 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49547Oretnom23 customer support system sql injection vulnerabilityCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=lo…EPSS 1.1%9.8CVE-2023-49970Oretnom23 customer support system sql injection vulnerabilityCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=sav…EPSS 0.82%9.4CVE-2025-70141Oretnom23 customer support system missing authentication for critical function vulnerabilitySourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe…EPSS 0.69%8.8CVE-2023-49978Oretnom23 customer support system improper access control vulnerabilityIncorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for…EPSS 0.84%8.8CVE-2023-49546Oretnom23 customer support system sql injection vulnerabilityCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.EPSS 0.76%8.8CVE-2023-50070Oretnom23 customer support system sql injection vulnerabilitySourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department…EPSS 0.79%8.7CVE-2025-40728Oretnom23 customer support system sql injection vulnerabilitySQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and dele…EPSS 0.50%7.5CVE-2023-49545Oretnom23 customer support system improper access control vulnerabilityA directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application witho…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2023-49548), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.