vendor:
Best Support System
by:
Ex.Mi
5.4
CVSS
MEDIUM
Persistent XSS
79
CWE
Product Name: Best Support System
Affected Version From: 3.0.4
Affected Version To: 3.0.4
Patch Exists: YES
Related CWE: CVE-2020-24963
CPE: a:appsbd:best_support_system:3.0.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2020
Best Support System 3.0.4 – ‘ticket_body’ Persistent XSS (Authenticated)
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version — v3.0.4. The vulnerability can be exploited by sending a malicious payload in the 'ticket_body' parameter of a POST request.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.