PT-2026-96098 · Git+1 · Community-Skeleton+1

·

CVE-2025-71420

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions UVdesk core-framework versions prior to 1.1.7
Description An authorization bypass exists in the saved reply endpoint. Authenticated users with the ROLE AGENT role can enumerate saved reply identifiers to access and read content restricted to support groups and teams to which they do not belong.
Recommendations Update UVdesk core-framework to version 1.1.7 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71420

Affected Products

Community-Skeleton
Core-Framework