uvdesk core-framework

3 known vulnerabilities in uvdesk core-framework, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2025-71421 CVSS 8.6 high UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents…
  • CVE-2025-71420 CVSS 5.3 medium UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated…
  • CVE-2025-71419 CVSS 5.1 medium UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier…