UVdesk core-framework 1.1.7 版本之前存在一个存储型跨站脚本(XSS)漏洞,该漏洞位于 操作中的 SwiftMailer 配置标识符参数。拥有 角色的攻击者可以在标识符字段中注入恶意脚本,这些脚本会被持久化存储,并在其他成员访问配置更新页面时执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| uvdesk | community-skeleton | < 1.1.8 |
affected |
1.1.8 |
unaffected | ||
| uvdesk | core-framework | < 1.1.7 |
affected |
1.1.7 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| uvdesk | core-framework | 0 ~ 1.1.7 | - |
|
| uvdesk | community-skeleton | 0 ~ 1.1.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-71421 | 7.2 HIGH | UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent |
| CVE-2025-71420 | 4.3 MEDIUM | UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply |
No comments yet