CVE-2026-105029: fallo de gravedad media en uvdesk support-center-bundle
UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVEs relacionadas — uvdesk support-center-bundle
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-92805CRITICALUVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation WizardEPSS 0.6%CVE-2025-71421HIGHUVdesk core-framework before 1.1.7 Privilege Escalation via editAgentEPSS 0.4%CVE-2025-71420MEDIUMUVdesk core-framework before 1.1.7 Authorization Bypass via Saved ReplyEPSS 0.3%CVE-2025-71419MEDIUMUVdesk core-framework before 1.1.7 Stored XSS via SwiftMailerEPSS 0.2%
Referencias
https://github.com/uvdesk/support-center-bundlehttps://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551fhttps://hackmd.io/@leediay/idor-rate-ticket_uvdeskhttps://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint