Privilege Escalation in UVdesk Core-Framework by UVdesk
CVE-2025-71421
8.6HIGH
What is CVE-2025-71421?
The UVdesk core-framework prior to version 1.1.7 is susceptible to a privilege escalation vulnerability found in the editAgent endpoint. This flaw enables agents with agent-management privileges to augment their role to administrator by submitting their account identifier with a manipulated role parameter. As a consequence, an attacker could gain unrestricted administrative control over agents, ticketing processes, and mail configurations, posing significant risks to the integrity of the system.
Affected Version(s)
community-skeleton 0 < 1.1.8
core-framework 0 < 1.1.7
community-skeleton 1.1.8
