CVE-2019-20222: Sitracker Support Incident Tracker

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.

Affected products

  • Sitracker Support Incident Tracker: version 3.67 only

Published 2020-01-02. Last modified 2026-06-17.