First published: Fri Aug 15 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kayako SupportSuite | =3.10.00 | |
Kayako SupportSuite | =3.11.01 | |
Kayako SupportSuite | <=3.20.02 | |
Kayako SupportSuite | =3.11.00 | |
Kayako SupportSuite | =3.10.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.