PT-2026-94079 · Unknown · Uvdesk Community Skeleton
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UVdesk Community Skeleton versions prior to 1.1.9
Description
The software fails to authenticate or validate the installation state on wizard endpoints within the
ConfigureHelpdesk controller actions. This allows unauthenticated attackers to repoint the database and create super administrator accounts by submitting crafted requests to these wizard endpoints, resulting in full control of the instance.Recommendations
Update UVdesk Community Skeleton to version 1.1.9 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uvdesk Community Skeleton