Search

Find a vulnerability

Search criteria

    6 vulnerabilities found for community-skeleton by uvdesk

    CVE-2026-105029 (GCVE-0-2026-105029)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
    Summary
    UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    uvdesk support-center-bundle Affected: 0 , < 1.1.3.3 (custom)
    Unaffected: 1.1.3.3 (custom)
    Create a notification for this product.
    uvdesk community-skeleton Affected: 0 , < 1.1.8 (semver)
    Unaffected: 1.1.8 (semver)
    Create a notification for this product.
    Date Public
    2025-06-06 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/support-center-bundle",
              "product": "support-center-bundle",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.3.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.3.3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/community-skeleton",
              "product": "community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.1.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "leediay153"
            }
          ],
          "datePublic": "2025-06-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers\u0027 tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:49.296Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551f"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://hackmd.io/@leediay/idor-rate-ticket_uvdesk"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/uvdesk/support-center-bundle"
            },
            {
              "name": "VulnCheck Advisory: UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint"
            }
          ],
          "title": "UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105029",
        "datePublished": "2026-10-02T23:28:49.296Z",
        "dateReserved": "2026-10-02T21:13:54.347Z",
        "dateUpdated": "2026-10-02T23:28:49.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-71421 (GCVE-0-2025-71421)

    Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-21 20:46
    VLAI
    Title
    UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
    Summary
    UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 16:42 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    uvdesk core-framework Affected: 0 , < 1.1.7 (semver)
    Unaffected: 1.1.7 (semver)
    Create a notification for this product.
    uvdesk community-skeleton Affected: 0 , < 1.1.8 (semver)
    Unaffected: 1.1.8 (semver)
    Create a notification for this product.
    Date Public
    2025-05-29 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-71421",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T16:42:47.306954Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T20:46:19.637Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/core-framework",
              "product": "core-framework",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.7",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/community-skeleton",
              "product": "community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.1.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "leediay153"
            }
          ],
          "datePublic": "2025-05-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-21T13:43:35.237Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55"
            },
            {
              "name": "editAgent role assignment at v1.1.6",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282"
            },
            {
              "name": "Reporter write-up",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://hackmd.io/@leediay/B1Cz5voFGg"
            },
            {
              "name": "core-framework v1.1.7 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/uvdesk/core-framework/releases/tag/v1.1.7"
            },
            {
              "name": "community-skeleton v1.1.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/uvdesk/core-framework"
            },
            {
              "name": "VulnCheck Advisory: UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent"
            }
          ],
          "title": "UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-71421",
        "datePublished": "2026-09-21T13:43:35.237Z",
        "dateReserved": "2026-09-21T13:09:23.156Z",
        "dateUpdated": "2026-09-21T20:46:19.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-71420 (GCVE-0-2025-71420)

    Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-21 14:14
    VLAI
    Title
    UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply
    Summary
    UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 14:13 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    uvdesk core-framework Affected: 0 , < 1.1.7 (semver)
    Unaffected: 1.1.7 (semver)
    Create a notification for this product.
    uvdesk community-skeleton Affected: 0 , < 1.1.8 (semver)
    Unaffected: 1.1.8 (semver)
    Create a notification for this product.
    Date Public
    2025-06-02 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-71420",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T14:13:37.762496Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T14:14:06.582Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://hackmd.io/@leediay/B1Cz5voFGg"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/core-framework",
              "product": "core-framework",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.7",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/community-skeleton",
              "product": "community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.1.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "leediay153"
            }
          ],
          "datePublic": "2025-06-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-21T13:43:34.312Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d"
            },
            {
              "name": "getSavedReplyContent at v1.1.6",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Services/TicketService.php#L1752-L1759"
            },
            {
              "name": "loadTicketSavedReplies at v1.1.6",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/TicketXHR.php#L838-L850"
            },
            {
              "name": "Reporter write-up",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://hackmd.io/@leediay/B1Cz5voFGg"
            },
            {
              "name": "core-framework v1.1.7 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/uvdesk/core-framework/releases/tag/v1.1.7"
            },
            {
              "name": "community-skeleton v1.1.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/uvdesk/core-framework"
            },
            {
              "name": "VulnCheck Advisory: UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-authorization-bypass-via-saved-reply"
            }
          ],
          "title": "UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-71420",
        "datePublished": "2026-09-21T13:43:34.312Z",
        "dateReserved": "2026-09-21T13:09:22.541Z",
        "dateUpdated": "2026-09-21T14:14:06.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-71419 (GCVE-0-2025-71419)

    Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-24 13:25
    VLAI
    Title
    UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer
    Summary
    UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 13:25 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    uvdesk core-framework Affected: 0 , < 1.1.7 (semver)
    Unaffected: 1.1.7 (semver)
    Create a notification for this product.
    uvdesk community-skeleton Affected: 0 , < 1.1.8 (semver)
    Unaffected: 1.1.8 (semver)
    Create a notification for this product.
    Date Public
    2025-05-29 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-71419",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T13:25:26.776967Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T13:25:45.933Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/core-framework",
              "product": "core-framework",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.7",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/community-skeleton",
              "product": "community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.1.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "leediay153"
            }
          ],
          "datePublic": "2025-05-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-21T13:43:33.353Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/uvdesk/core-framework/commit/e5e92d1f5bdb24d1b96751213fb427035736371f"
            },
            {
              "name": "Unescaped render of the stored configuration at v1.1.6",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Resources/views/SwiftMailer/manageConfigurations.html.twig#L324"
            },
            {
              "name": "createMailerConfiguration at v1.1.6",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/SwiftMailer.php#L38-L46"
            },
            {
              "name": "Reporter write-up",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://hackmd.io/@leediay/B1Cz5voFGg"
            },
            {
              "name": "core-framework v1.1.7 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/uvdesk/core-framework/releases/tag/v1.1.7"
            },
            {
              "name": "community-skeleton v1.1.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/uvdesk/core-framework"
            },
            {
              "name": "VulnCheck Advisory: UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-stored-xss-via-swiftmailer"
            }
          ],
          "title": "UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-71419",
        "datePublished": "2026-09-21T13:43:33.353Z",
        "dateReserved": "2026-09-21T13:09:21.957Z",
        "dateUpdated": "2026-09-24T13:25:45.933Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92805 (GCVE-0-2026-92805)

    Vulnerability from cvelistv5 – Published: 2026-09-16 20:32 – Updated: 2026-09-19 01:52
    VLAI
    Title
    UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard
    Summary
    UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-19 01:50 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    uvdesk community-skeleton Affected: 0 , ≤ 1.1.8 (semver)
        cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-19T01:50:03.711095Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-19T01:52:49.216Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/community-skeleton",
              "product": "community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThanOrEqual": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "1.1.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "George Chen"
            }
          ],
          "datePublic": "2026-08-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T20:32:54.622Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #926",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/uvdesk/community-skeleton/issues/926"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/uvdesk/community-skeleton"
            },
            {
              "name": "the wizard XHR routes carry no authentication attribute",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/uvdesk/community-skeleton/blob/6f35040/src/Resources/config/routes.yaml#L1-L35"
            },
            {
              "name": "VulnCheck Advisory: UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/uvdesk-community-skeleton-through-1.1.8-missing-authentication-on-the-installation-wizard"
            }
          ],
          "title": "UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-92805",
        "datePublished": "2026-09-16T20:32:54.622Z",
        "dateReserved": "2026-09-16T19:47:14.880Z",
        "dateUpdated": "2026-09-19T01:52:49.216Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-3137 (GCVE-0-2024-3137)

    Vulnerability from cvelistv5 – Published: 2024-04-02 00:00 – Updated: 2024-09-06 16:21
    VLAI
    Title
    Improper Privilege Management in uvdesk/community-skeleton
    Summary
    Improper Privilege Management in uvdesk/community-skeleton
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-08 14:23 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    uvdesk uvdesk/community-skeleton Affected: unspecified , ≤ latest (custom)
    Create a notification for this product.
    uvdesk community-skeleton Affected: 0 , < * (custom)
        cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:32:42.702Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://huntr.com/bounties/faf74783-644c-40cd-aa98-2239e5fafcd1"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "community-skeleton",
                "vendor": "uvdesk",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3137",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-08T14:23:29.976445Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-06T16:21:28.198Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "uvdesk/community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThanOrEqual": "latest",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper Privilege Management in uvdesk/community-skeleton"
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-02T00:00:14.584Z",
            "orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
            "shortName": "@huntr_ai"
          },
          "references": [
            {
              "url": "https://huntr.com/bounties/faf74783-644c-40cd-aa98-2239e5fafcd1"
            }
          ],
          "source": {
            "advisory": "faf74783-644c-40cd-aa98-2239e5fafcd1",
            "discovery": "EXTERNAL"
          },
          "title": "Improper Privilege Management in uvdesk/community-skeleton"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
        "assignerShortName": "@huntr_ai",
        "cveId": "CVE-2024-3137",
        "datePublished": "2024-04-02T00:00:14.584Z",
        "dateReserved": "2024-04-01T16:04:58.221Z",
        "dateUpdated": "2024-09-06T16:21:28.198Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }