Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-71421 1 Uvdesk 2 Community-skeleton, Core-framework 2026-09-22 7.2 High
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
CVE-2025-71419 1 Uvdesk 2 Community-skeleton, Core-framework 2026-09-21 5.4 Medium
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
CVE-2025-71420 1 Uvdesk 2 Community-skeleton, Core-framework 2026-09-21 4.3 Medium
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.