Authorization Bypass in UVdesk Core Framework Affects Multiple Support Groups
CVE-2025-71420
5.3MEDIUM
What is CVE-2025-71420?
The UVdesk core-framework prior to version 1.1.7 is vulnerable to an authorization bypass flaw that allows authenticated agents to gain unauthorized access to saved replies intended for other support groups. This vulnerability enables users with the ROLE_AGENT to enumerate saved reply identifiers, compromising the confidentiality of sensitive content that is meant for specific teams. As a result, organizations using vulnerable versions are at risk of exposing internal information across their support structures. Immediate updates to version 1.1.7 or later are recommended to mitigate this security threat.
Affected Version(s)
community-skeleton 0 < 1.1.8
core-framework 0 < 1.1.7
community-skeleton 1.1.8
