UVdesk core-framework 1.1.7 之前的版本在“已保存回复”端点中存在一个授权绕过漏洞,允许已认证的代理访问其他支持组受限的已保存回复。具有 ROLE_AGENT 角色的攻击者可以枚举已保存回复的标识符,并读取他们不属于的支持组和团队的受限内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| uvdesk | community-skeleton | < 1.1.8 |
affected |
1.1.8 |
unaffected | ||
| uvdesk | core-framework | < 1.1.7 |
affected |
1.1.7 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| uvdesk | core-framework | 0 ~ 1.1.7 | - |
|
| uvdesk | community-skeleton | 0 ~ 1.1.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-71421 | 7.2 HIGH | UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent |
| CVE-2025-71419 | 5.4 MEDIUM | UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer |
No comments yet