CVE-2019-20221: Sitracker Support Incident Tracker

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.

Affected products

  • Sitracker Support Incident Tracker: version 3.67 only

Published 2020-01-02. Last modified 2026-06-17.