CVE-2025-71419

Summary

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.

Affected Software

VendorProductVersion RangeStatus
uvdeskcore-framework0 < 1.1.7affected
uvdeskcore-framework1.1.7unaffected
uvdeskcommunity-skeleton0 < 1.1.8affected
uvdeskcommunity-skeleton1.1.8unaffected

Weaknesses

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References