Customer Support System 1.0 - Directory Listing# CVE-2023-49545
# Customer Support System 1.0 - Directory Listing
**Description**: A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authentication/authorization.
**Vulnerable Product Version**: Customer Support System 1.0
**CVE Author**: Geraldo Alcântara
**Date**: 28/11/2023
**Confirmed on**: 19/12/2023
**CVE**: CVE-2023-49545
**Tested on**: Windows
### Steps to reproduce:
1. Navigate to URL: http://{IP}/customer_support/database/ or http://{IP}/customer_support/assets/. I found out that many important files of application can be accessed directly from this directory listing.
Accessing the directory /database/

Accessing the directory /assets/

Discoverer(s)/Credits:
Geraldo Alcântara
[4.0K] /data/pocs/7b5c14cd76470261cbed7e80ae1395bd4156ef7b
└── [1.1K] README.md
0 directories, 1 file