Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-14028
HistoryMar 12, 2024 - 12:00 a.m.

Customer Support System Cross-Site Scripting Vulnerability (CNVD-2024-14028)

2024-03-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
cross-site scripting
customer support system
vulnerability
oretnom23 personal developer
filtering
web script
html
exploitation
subject parameter

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Customer Support System is a customer support system by oretnom23 Personal Developer that helps a particular business or company to provide customer support after a customer has purchased a product from them. Customer Support System suffers from a cross-site scripting vulnerability that stems from the application’s lack of effective filtering and escaping of user-supplied data, which can be exploited by an attacker to inject a crafted payload to execute arbitrary web script or HTML via the subject parameter in customer_support/index.php.

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%