Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-71421— UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent

Quick assessment

Affected
uvdesk core-framework
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

UVdesk core-framework 1.1.7 版本之前存在一个不当权限管理漏洞,该漏洞出现在 接口中,允许具有代理管理权限的代理人员将其自身角色提升为管理员。攻击者可以通过提交自己的账户标识,并将 参数设置为 ,从而获得对代理、工单和邮件配置的全部管理员控制权限。

CVSS 7.2 · High EPSS 0.44% · P36

Possible ATT&CK Techniques 1 AI

T1098 · Account Manipulation

Affected Version Matrix 4

VendorProduct Version RangeStatus
uvdesk community-skeleton < 1.1.8 affected
1.1.8 unaffected
uvdesk core-framework < 1.1.7 affected
1.1.7 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-71421

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
Source: CVE Program / CVE List V5
Vulnerability Description
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
uvdesk core-framework 0 ~ 1.1.7 -
uvdesk community-skeleton 0 ~ 1.1.8 -

II. Public POCs for CVE-2025-71421

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71421

请登录查看更多情报信息。

Patches & Fixes for CVE-2025-71421 (1)

Other References for CVE-2025-71421 (5)

Same Patch Batch · uvdesk · 2026-09-21 · 3 CVEs total

CVE-2025-71419 5.4 MEDIUM UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer
CVE-2025-71420 4.3 MEDIUM UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply

IV. Related Vulnerabilities

V. Comments for CVE-2025-71421

No comments yet


Leave a comment