First published: Mon Oct 23 2023(Updated: )
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webkul Uvdesk | =1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37636 is a stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1.
CVE-2023-37636 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
The severity of CVE-2023-37636 is medium with a CVSS score of 5.4.
To fix CVE-2023-37636, you should update UVDesk Community Skeleton to a version that includes the security patch.
You can find more information about CVE-2023-37636 at the following reference: [CVE-2023-37636](https://www.esecforte.com/cve-2023-37636-stored-cross-site-scripting/)