Impact
Perfect Support Ticketing & Document Management System up to version 1.7 is vulnerable possess Agent‑level rights can place malicious scripts into the Notes field of support tickets. When any user – including Superadmin – views those tickets, the payload executes in the victim’s browser, giving the attacker the ability to hijack that user’s session or perform unauthorized actions on the system.
Affected Systems
The flaw affects Ultimate Fosters’ Perfect Support Ticketing & Document Management System through version 1.7. All earlier releases prior to the remediation contain the same vulnerable Notes field implementation.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1 and is not listed in the CISA KEV catalog. The EPSS score is less than 1%. Because the exploit requires an authenticated Agent user, attackers must first log in, but once that is achieved the stored script automatically runs for any viewer of the ticket. This ranges from user session theft to unauthorized actions on the system. The low EPSS value suggests that exploitation is not heavily automated, but the stored nature of the attack means that a single successful injection could impact all users who access the affected notes.
OpenCVE Enrichment