AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-3700

MEDIUM · CVSS 4.3 EPSS 4.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-08-15 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. It may be remotely exploitable.

CVE
CVE-2008-3700
Severity
MEDIUM
CVSS
4.3
EPSS
4.10%

Original NVD Description

Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.