Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.
| Software | From | Fixed in |
|---|---|---|
| kayako / esupport | 2.1.8 | 2.1.8.x |
| kayako / esupport | 2.2 | 2.2.x |
| kayako / esupport | 2.3 | 2.3.x |
| kayako / esupport | 2.1.2 | 2.1.2.x |
| kayako / esupport | 2.2.5 | 2.2.5.x |