CVE-2025-71419
EUVD-2025-21097521.09.2026, 14:17
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References