Stored XSS Vulnerability in URVE Smart Office
CVE-2025-10348

5.1MEDIUM

Key Information:

Vendor

Eveo

Vendor
CVE Published:
30 October 2025

What is CVE-2025-10348?

URVE Smart Office is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability within its report problem functionality. This allows an attacker with limited privileges to upload a malicious SVG file. When a victim accesses the URL of this uploaded resource, the malicious payload will execute, potentially compromising the victim's data. This vulnerability is accessible to anyone without authentication. The issue was addressed in version 1.1.24 of the software.

Affected Version(s)

URVE Smart Office 0 < 1.1.24

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anna Błaszczak (Alior Bank)
Ksawery Kehl (Alior Bank)
.
CVE-2025-10348 : Stored XSS Vulnerability in URVE Smart Office