CVE-2026-105029
- EPSS 0.2%
- Veröffentlicht 02.10.2026 23:28:49
- Zuletzt bearbeitet 06.10.2026 17:17:16
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitr...
CVE-2025-71421
- EPSS 0.44%
- Veröffentlicht 21.09.2026 13:43:35
- Zuletzt bearbeitet 22.09.2026 20:43:58
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own accoun...
CVE-2025-71420
- EPSS 0.3%
- Veröffentlicht 21.09.2026 13:43:34
- Zuletzt bearbeitet 22.09.2026 20:43:58
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply i...
CVE-2025-71419
- EPSS 0.18%
- Veröffentlicht 21.09.2026 13:43:33
- Zuletzt bearbeitet 24.09.2026 14:17:10
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the iden...
CVE-2026-92805
- EPSS 0.35%
- Veröffentlicht 16.09.2026 20:32:54
- Zuletzt bearbeitet 22.09.2026 20:43:58
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by su...
CVE-2024-3137
- EPSS 0.36%
- Veröffentlicht 02.04.2024 01:15:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Privilege Management in uvdesk/community-skeleton
CVE-2023-37635
- EPSS 1.15%
- Veröffentlicht 23.10.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:12:03
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
CVE-2023-0265
- EPSS 1.6%
- Veröffentlicht 04.04.2023 22:15:07
- Zuletzt bearbeitet 13.02.2025 17:15:54
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
CVE-2023-0325
- EPSS 0.69%
- Veröffentlicht 04.04.2023 22:15:07
- Zuletzt bearbeitet 13.02.2025 17:15:54
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.
CVE-2023-1197
- EPSS 0.4%
- Veröffentlicht 06.03.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:38:39
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.