Cerberus Helpdesk vulnerable to XSS

Risk: Low
Local: Yes
Remote: Yes

CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

Inputs in the Cerberus Helpdesk is not properly sanitized, and XSS is possible in a lot of the systems input fields and url parameters. You can add XSS that will hit every user of the system, and even simple scripting tags like <script>alert('f')</script> is allowed PoC: http://www.SITE.example/tts2/clients.php?mode=search&sid=<sidvalue>&cont act_search=<script>alert('c')</script> Vendor?s site: http://www.webgroupmedia.com Please credit to: Preben Nyl?kken

