---
id: CVE-2026-63081
title: >-
  Perfect Support Ticketing & Document Management System through 1.7 contains a
  stored cross-site scripting vulnerability that allows authenticated attackers
  with Agent-level privileges to inject malicious payloads into the Notes field
  of …
summary: >-
  Perfect Support Ticketing & Document Management System through 1.7 contains a
  stored cross-site scripting vulnerability that allows authenticated attackers
  with Agent-level privileges to inject malicious payloads into the Notes field
  of …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-07-16'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63081'
references:
  - url: >-
      https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-63081
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/perfect-support-ticketing-system-stored-xss-via-ticket-notes-field
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-63081
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00235
epssPercentile: 0.12865
ingestedAt: '2026-07-18T19:24:32.138Z'
---

## Overview

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
