SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-63081

MEDIUM · CVSS 5.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Perfect Support Ticketing & Document Management System versions up to 1.7 are vulnerable to a stored cross-site scripting (XSS) flaw that allows authenticated users with Agent-level privileges to inject malicious scripts into the Notes field of support tickets. This vulnerability can lead to session hijacking or unauthorized actions when other users, including Superadmin accounts, view the compromised ticket notes. Organizations using this system should prioritize remediation to protect against potential exploitation by malicious actors.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63081
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.