Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject arbitrary web script or HTML via certain vectors, possibly a crafted ticket description.
- http://st2tea.blogspot.com/2012/03/kayako-fusion-cross-site-scripting.html
No PoCs found on GitHub currently.