Stored Cross-Site Scripting in Perfect Support Ticketing & Document Management System
CVE-2026-63081

5.1MEDIUM

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-63081?

The Perfect Support Ticketing & Document Management System version 1.7 contains a serious vulnerability that allows authenticated users with Agent-level privileges to exploit a stored cross-site scripting issue. By injecting malicious scripts into the Notes field of support tickets, attackers can compromise the browser context of any user who subsequently views those notes. This not only endangers Superadmin users but may also lead to session hijacking or unauthorized actions on behalf of the victim, ultimately jeopardizing the security of sensitive information within the system.

Affected Version(s)

Perfect Support Ticketing & Document Management System 0 <= 1.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaron Amran Bin Amiruddin
Shahrul Nizam Bin Shahrin
.