Junglewise Threat Intelligence

CVE-2026-63081: Ultimate Fosters Perfect Support Ticketing System stored XSS in Notes field

CVE-2026-63081 · Severity: medium · CVSS 5.4 · Published 2026-07-16

Executive brief

A vulnerability in the Perfect Support Ticketing & Document Management System allows staff members with 'Agent' privileges to plant malicious code within support ticket notes. When a manager or administrator views these notes, the code executes in their browser, potentially allowing the attacker to hijack their session or perform unauthorized actions with higher administrative permissions. This could lead to a full takeover of the support system and exposure of sensitive customer data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the 'Notes' input field of the Perfect Support Ticketing & Document Management System through version 1.7. The root cause is improper neutralization of user-supplied input before it is rendered in the web interface. An authenticated attacker with Agent-level privileges can inject arbitrary JavaScript payloads into a ticket's notes. When another user, such as a Superadmin, views the affected ticket, the script executes in their browser context. This can be leveraged for session hijacking, horizontal privilege escalation (targeting other Agents), or vertical privilege escalation (targeting Superadmins).

Affected products

  • Ultimate Fosters Perfect Support Ticketing & Document Management System <= 1.7

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats