Junglewise Threat Intelligence

CVE-2025-71419: UVdesk core-framework stored cross-site scripting in SwiftMailer configuration

CVE-2025-71419 · Severity: medium · CVSS 5.4 · Published 2026-09-21

Technologies: UVdesk Core-Framework. Vendors: UVdesk.

Executive brief

UVdesk core-framework is a helpdesk ticketing system framework. An agent with restricted permissions can inject malicious scripts into the mail configuration identifier field, which are then executed when administrators or other agents access the configuration page, potentially leading to account compromise or unauthorized actions.

Technical details

A stored XSS vulnerability exists in the createMailerConfiguration action's identifier parameter, allowing attackers with ROLE_AGENT to inject persistent malicious scripts. The injected payload is executed in the browsers of other users accessing the SwiftMailer configuration update page. The vulnerability was patched in version 1.1.8, which includes fixes for cross-site scripting security issues.

Affected products

  • UVdesk core-framework before 1.1.7

Timeline

  • 2025-09-21: disclosed
  • 2025-09-19: patched: fix available in version 1.1.8

References

Related threats