Stored XSS Vulnerability in URVE Smart Office
CVE-2025-10348
5.1MEDIUM
What is CVE-2025-10348?
URVE Smart Office is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability within its report problem functionality. This allows an attacker with limited privileges to upload a malicious SVG file. When a victim accesses the URL of this uploaded resource, the malicious payload will execute, potentially compromising the victim's data. This vulnerability is accessible to anyone without authentication. The issue was addressed in version 1.1.24 of the software.
Affected Version(s)
URVE Smart Office 0 < 1.1.24
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anna Błaszczak (Alior Bank)
Ksawery Kehl (Alior Bank)
