Impact
The vulnerability is a persistent XSS flaw in the support ticket module of Rocket LMS 1.1. An authenticated user can craft a malicious script and submit it via the ticket title field. When other users view the ticket history, the script executes in their browsers, which may lead to session hijacking or phishing attempts. The weakness corresponds to input handling failures identified as CWE‑79.
Affected Systems
Rocketsoft’s Rocket LMS version 1.1 is affected. The flaw resides in the support ticket subsystem used by authenticated users to create and read tickets. No other versions or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. No EPSS data is available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is documented. The likely attack vector involves an authenticated attacker creating a ticket; the exploitation requires no special conditions beyond using the standard support ticket interface. Because the payload is stored and executed on other users’ browsers, the impact is mainly confusion, possible loss of session cookies, and phishing opportunities.
OpenCVE Enrichment