Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SourceCodester Customer Support System 安全漏洞
Vulnerability Description
SourceCodester Customer Support System是SourceCodester开源的一个客户支持系统。 SourceCodester Customer Support System 1.0版本存在安全漏洞,该漏洞源于ajax.php中的AJAX调度器缺乏身份验证和授权检查,可能导致未经验证的攻击者执行敏感操作和未经授权的数据修改。
CVSS Information
N/A
Vulnerability Type
N/A