Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Uvdesk core-framework
|
|
| Vendors & Products |
Uvdesk core-framework
|
Mon, 21 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page. | |
| Title | UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer | |
| First Time appeared |
Uvdesk
Uvdesk community-skeleton |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uvdesk
Uvdesk community-skeleton |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T13:43:33.353Z
Reserved: 2026-09-21T13:09:21.957Z
Link: CVE-2025-71419
No data.
Status : Received
Published: 2026-09-21T14:17:14.303
Modified: 2026-09-21T14:17:14.303
Link: CVE-2025-71419
No data.
OpenCVE Enrichment
Updated: 2026-09-21T19:23:53Z