Vulnerability Details CVE-2023-0325
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 47.8%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-0325
-
cpe:2.3:a:uvdesk:community-skeleton:1.1.1