CVE-2023-0325

MEDIUM6.1EPSS 0.78%

Uvdesk vulnerable to stored cross-site scripting (XSS)

Published: 4/5/2023Modified: 2/13/2025
Also known as:GHSA-fwhv-9phj-wrj5

Description

Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (3)