UVdesk core-framework 1.1.7 版本之前存在一个不当权限管理漏洞,该漏洞出现在 接口中,允许具有代理管理权限的代理人员将其自身角色提升为管理员。攻击者可以通过提交自己的账户标识,并将 参数设置为 ,从而获得对代理、工单和邮件配置的全部管理员控制权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| uvdesk | community-skeleton | < 1.1.8 |
affected |
1.1.8 |
unaffected | ||
| uvdesk | core-framework | < 1.1.7 |
affected |
1.1.7 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| uvdesk | core-framework | 0 ~ 1.1.7 | - |
|
| uvdesk | community-skeleton | 0 ~ 1.1.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-71419 | 5.4 MEDIUM | UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer |
| CVE-2025-71420 | 4.3 MEDIUM | UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply |
No comments yet