Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cerberus_helpdesk | Cerberus | 2.7 (including) | 2.7 (including) |
Cerberus_helpdesk | Cerberus | 2.7.1_development_release (including) | 2.7.1_development_release (including) |