{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/customer-support-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:oretnom23:customer_support_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-49970"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Customer Support System (1.0)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","sql-injection","cve"],"_cs_type":"advisory","_cs_vendors":["oretnom23"],"content_html":"\u003cp\u003eCVE-2023-49970 is a critical SQL injection vulnerability affecting Customer Support System version 1.0. The vulnerability exists within the 'save_ticket' operation, specifically within the 'subject' parameter handled by the '/customer_support/ajax.php' endpoint. An unauthenticated attacker can supply crafted input containing SQL syntax to manipulate database queries. Given the application's design, this vulnerability allows for unauthorized data access, modification, or potential full database compromise. The availability of public exploit code targeting this specific parameter significantly increases the risk to organizations running this software.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to the public-facing ticketing portal (/customer_support/index.php?page=new_ticket).\u003c/li\u003e\n\u003cli\u003eAttacker prepares a POST request to the '/customer_support/ajax.php' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker targets the 'action=save_ticket' parameter to initiate the ticket creation process.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious SQL payload into the 'subject' field, such as a time-based blind SQL injection string like \u0026quot;'+(select*from(select(sleep(5)))a)+'\u0026quot;.\u003c/li\u003e\n\u003cli\u003eThe application fails to sanitize the input, passing the concatenated SQL string directly to the backend MySQL database.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected command, leading to unauthorized operations or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full compromise of the application's backend database. Attackers can exfiltrate sensitive customer support data, modify ticket records, or potentially perform administrative actions within the application. This poses a significant threat to the confidentiality, integrity, and availability of information stored within the Customer Support System.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all instances of the Customer Support System version 1.0. Until a patch is applied, restrict access to the '/customer_support/' directory via WAF rules to prevent unauthorized HTTP POST requests to the 'ajax.php' endpoint. Deploy the provided Sigma rule to detect attempts at SQL injection via the 'subject' parameter.\u003c/p\u003e\n","date_modified":"2026-08-31T20:06:37Z","date_published":"2026-08-31T20:06:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-49970/","summary":"CVE-2023-49970 is a critical SQL injection vulnerability in the Customer Support System version 1.0 allowing unauthenticated attackers to execute arbitrary database commands via the 'subject' parameter.","title":"Critical SQL Injection in Customer Support System 1.0","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-49970/"}],"language":"en","title":"CraftedSignal Threat Feed - Customer Support System (1.0)","version":"https://jsonfeed.org/version/1.1"}