GHSA-vv73-x849-w3ggMediumCVSS 5.4

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the...

Published
September 21, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.

🔗 References (10)