CVE-2009-3567
06.10.2009, 20:30
Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a different vector than CVE-2007-1145.
| Vendor | Product | Version |
|---|---|---|
| kayako | esupport | 𝑥 ≤ 3.60.04 |
| kayako | esupport | 2.1.2 |
| kayako | esupport | 2.1.8 |
| kayako | esupport | 2.2 |
| kayako | esupport | 2.2.5 |
| kayako | esupport | 2.3 |
| kayako | esupport | 2.3.1 |
| kayako | esupport | 3.00.13 |
| kayako | esupport | 3.00.90 |
| kayako | esupport | 3.04.10 |
| kayako | supportsuite | 𝑥 ≤ 3.60.04 |
| kayako | supportsuite | 3.00.26 |
| kayako | supportsuite | 3.00.32 |
| kayako | supportsuite | 3.10.00 |
| kayako | supportsuite | 3.10.02 |
| kayako | supportsuite | 3.11.00 |
| kayako | supportsuite | 3.11.01 |
| kayako | supportsuite | 3.20.02 |
| kayako | supportsuite | 3.50.06 |
𝑥
= Vulnerable software versions
References