5.3

CVE-2026-105029

UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleruvdesk
≫
Produkt support-center-bundle
Default Statusunaffected
Version 0
Version < 1.1.3.3
Status affected
Version 1.1.3.3
Status unaffected
Herstelleruvdesk
≫
Produkt community-skeleton
Default Statusunaffected
Version 0
Version < 1.1.8
Status affected
Version 1.1.8
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.089
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 5.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551f
https://hackmd.io/@leediay/idor-rate-ticket_uvdesk
https://github.com/uvdesk/support-center-bundle
https://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint