CVE-2025-40728
16.06.2025, 09:15
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint.
Awaiting analysis
This vulnerability is currently awaiting analysis.