CVE-2025-71419: Uvdesk Community-Skeleton

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members access the configuration update page.

Affected products

  • Uvdesk Community-Skeleton: before 1.1.8 (fixed in 1.1.8)
  • Uvdesk Core-Framework: before 1.1.7 (fixed in 1.1.7)

Published 2026-09-21. Last modified 2026-09-24.