CVE-2025-31626
Executive Summary
CVE-2025-31626 exposes a reflected XSS flaw in Alisaleem252 Support Helpdesk Ticket System Lite (v ≤ 4.5.2). Improper input sanitization during page rendering allows attackers to inject malicious scripts via the ticket interface, enabling session hijacking, defacement, or data theft. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.1 (HIGH) - Published: 2025-04-03T14:15:38.067 - Last Modified: 2026-10-06T16:17:04.187
Original Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2.
"It is only with the heart that one can see rightly, what is essential is invisible to the eye."
— Antoine de Saint-Exupery