ALPHACON BBSGość · pl
← Podatności

Podatności / NVD · CVSS 5.1

CVE-2025-71419 · UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action.

Identyfikator
CVE-2025-71419
CVSS
5.1 MEDIUM
CISA KEV
nie ma w katalogu
Opublikowano
2026-09-21
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.