CyberRota Analysis
AI-GeneratedThe Perfect Support Ticketing & Document Management System versions up to 1.7 are vulnerable to a stored cross-site scripting (XSS) flaw that allows authenticated users with Agent-level privileges to inject malicious scripts into the Notes field of support tickets. This vulnerability can lead to session hijacking or unauthorized actions when other users, including Superadmin accounts, view the compromised ticket notes. Organizations using this system should prioritize remediation to protect against potential exploitation by malicious actors.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.