vendor:
eSupport
by:
Unknown
7.5
CVSS
HIGH
Input Validation
CWE
Product Name: eSupport
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
Input Validation Vulnerabilities in Kayako eSupport
Kayako eSupport is prone to multiple input validation vulnerabilities. One cross-site scripting and six SQL injection vulnerabilities. These issues may collectively threaten compromise of software and database security properties. Possible attacks include theft of cookie-based authentication credentials, exposure or modification of database information, and a potential for attacks against the underlying database implementation.
Mitigation:
It is recommended to update to the latest version of Kayako eSupport which includes patches for these vulnerabilities. Additionally, input validation should be implemented to prevent these types of vulnerabilities.