CVE-2026-63081
MEDIUMPerfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field
Title source: cnaDescription
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-63081
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/perfect-support-ticketing-system-stored-xss-via-ticket-notes-field
Scores
CVSS v3
5.4
EPSS
0.0014
EPSS Percentile
3.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
Ultimate Fosters/Perfect Support Ticketing & Document Management System
< 1.7
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026