CVE-2023-49544: ORETNOM23 Customer Support System

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.

Affected products

  • ORETNOM23 Customer Support System: version 1.0 only

Published 2024-03-01. Last modified 2026-06-17.