CVE-2023-0265: Uvdesk Community-Skeleton

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.

Affected products

  • Uvdesk Community-Skeleton: version 1.1.1 only

Published 2023-04-04. Last modified 2026-06-17.