Executive brief
UVdesk core-framework is a help desk platform component that manages support tickets and agent collaboration. An authorization flaw allows authenticated support agents to view saved replies belonging to other support groups they should not have access to, potentially exposing sensitive response templates and business information restricted to specific teams.
Technical details
The vulnerability is an authorization bypass in the saved reply endpoint that fails to properly validate whether an authenticated agent has permission to access replies restricted to other support groups. An attacker with ROLE_AGENT can enumerate saved reply identifiers through the endpoint and read content they are not authorized to access, without requiring additional privileges or user interaction. The fix is available in version 1.1.8 and later.
Affected products
- UVdesk core-framework before 1.1.8
Timeline
- 2025-09-21: disclosed
- 2025-09-19: patched: patch released in v1.1.8