Description
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
Published: 2026-09-21
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Uvdesk core-framework
Vendors & Products Uvdesk core-framework

Mon, 21 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
Title UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer
First Time appeared Uvdesk
Uvdesk community-skeleton
Weaknesses CWE-79
CPEs cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*
Vendors & Products Uvdesk
Uvdesk community-skeleton
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Uvdesk Community-skeleton Core-framework
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T13:25:45.933Z

Reserved: 2026-09-21T13:09:21.957Z

Link: CVE-2025-71419

cve-icon Vulnrichment

Updated: 2026-09-24T13:25:41.223Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T14:17:14.303

Modified: 2026-09-24T14:17:10.523

Link: CVE-2025-71419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:23:53Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')