PT-2026-96098 · Git+1 · Community-Skeleton+1
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
UVdesk core-framework versions prior to 1.1.7
Description
An authorization bypass exists in the saved reply endpoint. Authenticated users with the
ROLE AGENT role can enumerate saved reply identifiers to access and read content restricted to support groups and teams to which they do not belong.Recommendations
Update UVdesk core-framework to version 1.1.7 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Community-Skeleton
Core-Framework