Description
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.
Published: 2026-07-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Perfect Support Ticketing & Document Management System up to version 1.7 is vulnerable possess Agent‑level rights can place malicious scripts into the Notes field of support tickets. When any user – including Superadmin – views those tickets, the payload executes in the victim’s browser, giving the attacker the ability to hijack that user’s session or perform unauthorized actions on the system.

Affected Systems

The flaw affects Ultimate Fosters’ Perfect Support Ticketing & Document Management System through version 1.7. All earlier releases prior to the remediation contain the same vulnerable Notes field implementation.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1 and is not listed in the CISA KEV catalog. The EPSS score is less than 1%. Because the exploit requires an authenticated Agent user, attackers must first log in, but once that is achieved the stored script automatically runs for any viewer of the ticket. This ranges from user session theft to unauthorized actions on the system. The low EPSS value suggests that exploitation is not heavily automated, but the stored nature of the attack means that a single successful injection could impact all users who access the affected notes.

Generated by OpenCVE AI on July 31, 2026 at 01:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or latest release that removes the vulnerable Notes field handling.
  • If no patch is available, restrict or sanitize the Notes field input so that only plain text is stored, removing executable markup.
  • Implement a Content Security Policy that blocks inline script execution for Notes field or segregate it from the main ticket view to reduce the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Ultimate Fosters
Ultimate Fosters perfect Support Ticketing & Document Management System
Vendors & Products Ultimate Fosters
Ultimate Fosters perfect Support Ticketing & Document Management System

Sat, 18 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.
Title Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Ultimate Fosters Perfect Support Ticketing & Document Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-18T02:54:07.692Z

Reserved: 2026-07-15T15:45:44.600Z

Link: CVE-2026-63081

cve-icon Vulnrichment

Updated: 2026-07-18T02:53:51.759Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')