{"id":"CVE-2025-71421","published":"2026-09-21T14:17:14.897","lastModified":"2026-09-21T21:17:02.797","description":"UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-269"],"vendors":[],"products":[],"references":[{"url":"https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8","tags":[]},{"url":"https://github.com/uvdesk/core-framework","tags":[]},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282","tags":[]},{"url":"https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55","tags":[]},{"url":"https://github.com/uvdesk/core-framework/releases/tag/v1.1.7","tags":[]},{"url":"https://hackmd.io/@leediay/B1Cz5voFGg","tags":[]},{"url":"https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent","tags":[]}],"exploitRefs":[{"url":"https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8","tags":[]},{"url":"https://github.com/uvdesk/core-framework","tags":[]},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282","tags":[]},{"url":"https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55","tags":[]},{"url":"https://github.com/uvdesk/core-framework/releases/tag/v1.1.7","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows agents with agent-management privilege to escalate their role to administrator, gaining full administrative control.","exploitability":"Exploitation requires an authenticated agent with specific privileges and direct manipulation of the role parameter.","blast_radius":"If exploited, it could lead to complete system compromise affecting agents, tickets, and mail configurations.","remediation":"Update to UVdesk core-framework version 1.1.7 or later immediately.","tags":["privilege-escalation","web","admin-control"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:16:52.808Z"}}