UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6
exploitation probability
—
observed exploitation
nono source reports it
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References
https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8https://github.com/uvdesk/core-frameworkhttps://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55https://github.com/uvdesk/core-framework/releases/tag/v1.1.7https://hackmd.io/@leediay/B1Cz5voFGghttps://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent