CVE-2025-71420: UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLEAGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
UVdesk core-frameworkto a version that resolves this vulnerability.Fixed in 1.1.7
Event History
Frequently Asked Questions
Which users can exploit this issue?
An authenticated UVdesk user with the ROLE_AGENT role can exploit it. The issue affects agents who can reach the saved reply endpoint, including agents outside the support group or team to which a reply is restricted.
What information can be exposed?
An attacker can enumerate saved reply identifiers and read the content of saved replies restricted to other support groups or teams. The provided data indicates an information-disclosure impact, with no integrity or availability impact.
Are unauthenticated attackers affected?
No. Exploitation requires authentication and the ROLE_AGENT role; the supplied vector lists privileges as low and user interaction as not required.
What version resolves the issue?
Upgrade UVdesk core-framework to version 1.1.7 or later. Versions before 1.1.7 are identified as affected.