Description

Multiple cross-site scripting (XSS) vulnerabilities exist in Maian Support. Various parameters in the support ticket system are not properly sanitized before HTML output.

Impact

Attackers can inject malicious JavaScript into support tickets that executes when staff view the tickets, potentially leading to administrative account compromise.

Solution

Upgrade to the latest version of Maian Support.

References