Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-71421 | 1 Uvdesk | 2 Community-skeleton, Core-framework | 2026-09-22 | 7.2 High |
| UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration. | ||||
| CVE-2025-71419 | 1 Uvdesk | 2 Community-skeleton, Core-framework | 2026-09-21 | 5.4 Medium |
| UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page. | ||||
| CVE-2025-71420 | 1 Uvdesk | 2 Community-skeleton, Core-framework | 2026-09-21 | 4.3 Medium |
| UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to. | ||||
Page 1 of 1.