Stored Cross-Site Scripting in Perfect Support Ticketing & Document Management System
CVE-2026-63081
Key Information:
- Vendor
Ultimate Fosters
- Vendor
- CVE Published:
- 16 July 2026
Badges
What is CVE-2026-63081?
The Perfect Support Ticketing & Document Management System version 1.7 contains a serious vulnerability that allows authenticated users with Agent-level privileges to exploit a stored cross-site scripting issue. By injecting malicious scripts into the Notes field of support tickets, attackers can compromise the browser context of any user who subsequently views those notes. This not only endangers Superadmin users but may also lead to session hijacking or unauthorized actions on behalf of the victim, ultimately jeopardizing the security of sensitive information within the system.
Affected Version(s)
Perfect Support Ticketing & Document Management System 0 <= 1.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
