Description
|
|
A Cross Site Scripting vulnerability was reported in Kayako eSupport, which may be exploited by attackers to inject malicious HTML/Javascript code. This flaw is due to an input validation error in the "index.php" script when handling specially crafted "_i", "_c" and "_j" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.
|