UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page. | |
| Title | UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer | |
| First Time appeared |
Uvdesk
Uvdesk community-skeleton |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uvdesk
Uvdesk community-skeleton |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T13:43:33.353Z
Reserved: 2026-09-21T13:09:21.957Z
Link: CVE-2025-71419
No data.
Status : Received
Published: 2026-09-21T14:17:14.303
Modified: 2026-09-21T14:17:14.303
Link: CVE-2025-71419
No data.
OpenCVE Enrichment
No data.
Weaknesses