Search
Find a vulnerability
Search criteria
6 vulnerabilities found for community-skeleton by uvdesk
CVE-2026-105029 (GCVE-0-2026-105029)
Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
VLAI
EPSS
VEX
Title
UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
Summary
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
Severity
4.3 (Medium)
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/uvdesk/support-center-bundle/c… | patch |
| https://hackmd.io/@leediay/idor-rate-ticket_uvdesk | technical-description |
| https://github.com/uvdesk/support-center-bundle | product |
| https://www.vulncheck.com/advisories/uvdesk-suppo… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| uvdesk | support-center-bundle |
Affected:
0 , < 1.1.3.3
(custom)
Unaffected: 1.1.3.3 (custom) |
|
| uvdesk | community-skeleton |
Affected:
0 , < 1.1.8
(semver)
Unaffected: 1.1.8 (semver) |
Date Public
2025-06-06 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/support-center-bundle",
"product": "support-center-bundle",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.3.3",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1.3.3",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/community-skeleton",
"product": "community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2025-06-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers\u0027 tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T23:28:49.296Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551f"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/idor-rate-ticket_uvdesk"
},
{
"tags": [
"product"
],
"url": "https://github.com/uvdesk/support-center-bundle"
},
{
"name": "VulnCheck Advisory: UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint"
}
],
"title": "UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105029",
"datePublished": "2026-10-02T23:28:49.296Z",
"dateReserved": "2026-10-02T21:13:54.347Z",
"dateUpdated": "2026-10-02T23:28:49.296Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-71421 (GCVE-0-2025-71421)
Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-21 20:46
VLAI
EPSS
VEX
Title
UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
Summary
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 16:42 UTC
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/uvdesk/core-framework/commit/b… | patch |
| https://github.com/uvdesk/core-framework/blob/v1.… | technical-description |
| https://hackmd.io/@leediay/B1Cz5voFGg | third-party-advisory |
| https://github.com/uvdesk/core-framework/releases… | release-notes |
| https://github.com/uvdesk/community-skeleton/rele… | release-notes |
| https://github.com/uvdesk/core-framework | product |
| https://www.vulncheck.com/advisories/uvdesk-core-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| uvdesk | core-framework |
Affected:
0 , < 1.1.7
(semver)
Unaffected: 1.1.7 (semver) |
|
| uvdesk | community-skeleton |
Affected:
0 , < 1.1.8
(semver)
Unaffected: 1.1.8 (semver) |
Date Public
2025-05-29 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-71421",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T16:42:47.306954Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T20:46:19.637Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/core-framework",
"product": "core-framework",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.7",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/community-skeleton",
"product": "community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2025-05-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T13:43:35.237Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55"
},
{
"name": "editAgent role assignment at v1.1.6",
"tags": [
"technical-description"
],
"url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282"
},
{
"name": "Reporter write-up",
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/B1Cz5voFGg"
},
{
"name": "core-framework v1.1.7 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/uvdesk/core-framework/releases/tag/v1.1.7"
},
{
"name": "community-skeleton v1.1.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/uvdesk/core-framework"
},
{
"name": "VulnCheck Advisory: UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent"
}
],
"title": "UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2025-71421",
"datePublished": "2026-09-21T13:43:35.237Z",
"dateReserved": "2026-09-21T13:09:23.156Z",
"dateUpdated": "2026-09-21T20:46:19.637Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-71420 (GCVE-0-2025-71420)
Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-21 14:14
VLAI
EPSS
VEX
Title
UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply
Summary
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.
Severity
4.3 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 14:13 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/uvdesk/core-framework/commit/d… | patch |
| https://github.com/uvdesk/core-framework/blob/v1.… | technical-description |
| https://github.com/uvdesk/core-framework/blob/v1.… | technical-description |
| https://hackmd.io/@leediay/B1Cz5voFGg | third-party-advisory |
| https://github.com/uvdesk/core-framework/releases… | release-notes |
| https://github.com/uvdesk/community-skeleton/rele… | release-notes |
| https://github.com/uvdesk/core-framework | product |
| https://www.vulncheck.com/advisories/uvdesk-core-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| uvdesk | core-framework |
Affected:
0 , < 1.1.7
(semver)
Unaffected: 1.1.7 (semver) |
|
| uvdesk | community-skeleton |
Affected:
0 , < 1.1.8
(semver)
Unaffected: 1.1.8 (semver) |
Date Public
2025-06-02 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-71420",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T14:13:37.762496Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T14:14:06.582Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/B1Cz5voFGg"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/core-framework",
"product": "core-framework",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.7",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/community-skeleton",
"product": "community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2025-06-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T13:43:34.312Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d"
},
{
"name": "getSavedReplyContent at v1.1.6",
"tags": [
"technical-description"
],
"url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Services/TicketService.php#L1752-L1759"
},
{
"name": "loadTicketSavedReplies at v1.1.6",
"tags": [
"technical-description"
],
"url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/TicketXHR.php#L838-L850"
},
{
"name": "Reporter write-up",
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/B1Cz5voFGg"
},
{
"name": "core-framework v1.1.7 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/uvdesk/core-framework/releases/tag/v1.1.7"
},
{
"name": "community-skeleton v1.1.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/uvdesk/core-framework"
},
{
"name": "VulnCheck Advisory: UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-authorization-bypass-via-saved-reply"
}
],
"title": "UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2025-71420",
"datePublished": "2026-09-21T13:43:34.312Z",
"dateReserved": "2026-09-21T13:09:22.541Z",
"dateUpdated": "2026-09-21T14:14:06.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-71419 (GCVE-0-2025-71419)
Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-24 13:25
VLAI
EPSS
VEX
Title
UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer
Summary
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 13:25 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/uvdesk/core-framework/commit/e… | patch |
| https://github.com/uvdesk/core-framework/blob/v1.… | technical-description |
| https://github.com/uvdesk/core-framework/blob/v1.… | technical-description |
| https://hackmd.io/@leediay/B1Cz5voFGg | third-party-advisory |
| https://github.com/uvdesk/core-framework/releases… | release-notes |
| https://github.com/uvdesk/community-skeleton/rele… | release-notes |
| https://github.com/uvdesk/core-framework | product |
| https://www.vulncheck.com/advisories/uvdesk-core-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| uvdesk | core-framework |
Affected:
0 , < 1.1.7
(semver)
Unaffected: 1.1.7 (semver) |
|
| uvdesk | community-skeleton |
Affected:
0 , < 1.1.8
(semver)
Unaffected: 1.1.8 (semver) |
Date Public
2025-05-29 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-71419",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:25:26.776967Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T13:25:45.933Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/core-framework",
"product": "core-framework",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.7",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.7",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/community-skeleton",
"product": "community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "1.1.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.1.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2025-05-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T13:43:33.353Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/uvdesk/core-framework/commit/e5e92d1f5bdb24d1b96751213fb427035736371f"
},
{
"name": "Unescaped render of the stored configuration at v1.1.6",
"tags": [
"technical-description"
],
"url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Resources/views/SwiftMailer/manageConfigurations.html.twig#L324"
},
{
"name": "createMailerConfiguration at v1.1.6",
"tags": [
"technical-description"
],
"url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/SwiftMailer.php#L38-L46"
},
{
"name": "Reporter write-up",
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/B1Cz5voFGg"
},
{
"name": "core-framework v1.1.7 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/uvdesk/core-framework/releases/tag/v1.1.7"
},
{
"name": "community-skeleton v1.1.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/uvdesk/core-framework"
},
{
"name": "VulnCheck Advisory: UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-stored-xss-via-swiftmailer"
}
],
"title": "UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2025-71419",
"datePublished": "2026-09-21T13:43:33.353Z",
"dateReserved": "2026-09-21T13:09:21.957Z",
"dateUpdated": "2026-09-24T13:25:45.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92805 (GCVE-0-2026-92805)
Vulnerability from cvelistv5 – Published: 2026-09-16 20:32 – Updated: 2026-09-19 01:52
VLAI
EPSS
VEX
Title
UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard
Summary
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-19 01:50 UTC
CWE
- CWE-306 - Missing Authentication for Critical Function
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/uvdesk/community-skeleton/issues/926 | issue-tracking |
| https://github.com/uvdesk/community-skeleton | product |
| https://github.com/uvdesk/community-skeleton/blob… | technical-description |
| https://www.vulncheck.com/advisories/uvdesk-commu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| uvdesk | community-skeleton |
Affected:
0 , ≤ 1.1.8
(semver)
cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* |
Date Public
2026-08-26 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92805",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-19T01:50:03.711095Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-19T01:52:49.216Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/uvdesk/community-skeleton",
"product": "community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThanOrEqual": "1.1.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.1.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-08-26T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T20:32:54.622Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #926",
"tags": [
"issue-tracking"
],
"url": "https://github.com/uvdesk/community-skeleton/issues/926"
},
{
"tags": [
"product"
],
"url": "https://github.com/uvdesk/community-skeleton"
},
{
"name": "the wizard XHR routes carry no authentication attribute",
"tags": [
"technical-description"
],
"url": "https://github.com/uvdesk/community-skeleton/blob/6f35040/src/Resources/config/routes.yaml#L1-L35"
},
{
"name": "VulnCheck Advisory: UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/uvdesk-community-skeleton-through-1.1.8-missing-authentication-on-the-installation-wizard"
}
],
"title": "UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92805",
"datePublished": "2026-09-16T20:32:54.622Z",
"dateReserved": "2026-09-16T19:47:14.880Z",
"dateUpdated": "2026-09-19T01:52:49.216Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-3137 (GCVE-0-2024-3137)
Vulnerability from cvelistv5 – Published: 2024-04-02 00:00 – Updated: 2024-09-06 16:21
VLAI
EPSS
VEX
Title
Improper Privilege Management in uvdesk/community-skeleton
Summary
Improper Privilege Management in uvdesk/community-skeleton
Severity
7.1 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-08-08 14:23 UTC
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| uvdesk | uvdesk/community-skeleton |
Affected:
unspecified , ≤ latest
(custom)
|
|
| uvdesk | community-skeleton |
Affected:
0 , < *
(custom)
cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-01T19:32:42.702Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://huntr.com/bounties/faf74783-644c-40cd-aa98-2239e5fafcd1"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-3137",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-08-08T14:23:29.976445Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-06T16:21:28.198Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "uvdesk/community-skeleton",
"vendor": "uvdesk",
"versions": [
{
"lessThanOrEqual": "latest",
"status": "affected",
"version": "unspecified",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Privilege Management in uvdesk/community-skeleton"
}
],
"metrics": [
{
"cvssV3_0": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-04-02T00:00:14.584Z",
"orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"shortName": "@huntr_ai"
},
"references": [
{
"url": "https://huntr.com/bounties/faf74783-644c-40cd-aa98-2239e5fafcd1"
}
],
"source": {
"advisory": "faf74783-644c-40cd-aa98-2239e5fafcd1",
"discovery": "EXTERNAL"
},
"title": "Improper Privilege Management in uvdesk/community-skeleton"
}
},
"cveMetadata": {
"assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"assignerShortName": "@huntr_ai",
"cveId": "CVE-2024-3137",
"datePublished": "2024-04-02T00:00:14.584Z",
"dateReserved": "2024-04-01T16:04:58.221Z",
"dateUpdated": "2024-09-06T16:21:28.198Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}