{"id":"CVE-2025-71420","published":"2026-09-21T14:17:14.720","lastModified":"2026-09-21T15:17:27.707","description":"UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8","tags":[]},{"url":"https://github.com/uvdesk/core-framework","tags":[]},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/TicketXHR.php#L838-L850","tags":[]},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Services/TicketService.php#L1752-L1759","tags":[]},{"url":"https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d","tags":[]},{"url":"https://github.com/uvdesk/core-framework/releases/tag/v1.1.7","tags":[]},{"url":"https://hackmd.io/@leediay/B1Cz5voFGg","tags":[]},{"url":"https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-authorization-bypass-via-saved-reply","tags":[]},{"url":"https://hackmd.io/@leediay/B1Cz5voFGg","tags":[]}],"exploitRefs":[{"url":"https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8","tags":[]},{"url":"https://github.com/uvdesk/core-framework","tags":[]},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/TicketXHR.php#L838-L850","tags":[]},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Services/TicketService.php#L1752-L1759","tags":[]},{"url":"https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d","tags":[]},{"url":"https://github.com/uvdesk/core-framework/releases/tag/v1.1.7","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows authenticated agents to access restricted saved replies, potentially exposing sensitive information across support groups.","exploitability":"Exploitation requires an authenticated agent role and knowledge of saved reply identifiers; moderate effort needed.","blast_radius":"If exploited, it could lead to data leakage affecting multiple support groups and teams.","remediation":"Update to UVdesk core-framework version 1.1.7 or later to patch the authorization bypass vulnerability.","tags":["auth-bypass","web","info-leak","patch-available"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:32:15.823Z"}}