PT-2026-96097 · Git+1 · Community-Skeleton+1

·

CVE-2025-71419

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions UVdesk core-framework versions prior to 1.1.7
Description A stored cross-site scripting issue exists in the createMailerConfiguration action. Users with ROLE AGENT privileges can inject malicious scripts into the identifier parameter of the SwiftMailer configuration. This script is stored on the server and executes when other members view the configuration update page.
Recommendations Update UVdesk core-framework to version 1.1.7 or later. As a temporary mitigation, restrict access to the createMailerConfiguration action for users with ROLE AGENT privileges.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71419

Affected Products

Community-Skeleton
Core-Framework