CVE-2023-0265: Uvdesk Community-Skeleton
High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
Affected products
- Uvdesk Community-Skeleton: version 1.1.1 only
Published 2023-04-04. Last modified 2026-06-17.