CVE-2025-71420

Summary

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.

Affected Software

VendorProductVersion RangeStatus
uvdeskcore-framework0 < 1.1.7affected
uvdeskcore-framework1.1.7unaffected
uvdeskcommunity-skeleton0 < 1.1.8affected
uvdeskcommunity-skeleton1.1.8unaffected

Weaknesses

  • CWE-639: Authorization Bypass Through User-Controlled Key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References