Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
No PoCs from references.
- https://github.com/geraldoalcantara/CVE-2023-49546
- https://github.com/nomi-sec/PoC-in-GitHub