A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html | product |
https://cwe.mitre.org/data/definitions/548.html | not applicable |
https://github.com/geraldoalcantara/CVE-2023-49545 | third party advisory exploit |