Description
Multiple persistent input validation vulnerabilities are detected in the Kayako Fusion v4.51.1891 Web Application. The vulnerability typus allows an attacker to inject own malicious script code in the vulnerable module on application side (persistent). The vulnerabilities can be exploited with a privileged application user account and low or medium required user interaction.
Remediation
Upgrade to the latest version of Kayako Fusion.
References
Related Vulnerabilities
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-34798)
MySQL CVE-2021-35626 Vulnerability (CVE-2021-35626)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-9591)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-1581)