4.3
CVSSv2

CVE-2009-3567

Published: 06/10/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a different vector than CVE-2007-1145.

Vulnerable Product Search on Vulmon Subscribe to Product

kayako esupport 2.2.5

kayako esupport 2.3

kayako esupport 2.1.8

kayako supportsuite 3.10.02

kayako esupport 2.3.1

kayako esupport 3.00.13

kayako supportsuite 3.11.00

kayako supportsuite 3.00.26

kayako supportsuite 3.10.00

kayako esupport 3.04.10

kayako esupport 3.00.90

kayako supportsuite 3.20.02

kayako supportsuite 3.00.32

kayako esupport

kayako supportsuite

kayako esupport 2.2

kayako esupport 2.1.2

kayako supportsuite 3.11.01

kayako supportsuite 3.50.06