Stored XSS Vulnerability in UVDesk Community Skeleton v1.1.1 Allows Arbitrary Code Execution via Ticket Creation

Stored XSS Vulnerability in UVDesk Community Skeleton v1.1.1 Allows Arbitrary Code Execution via Ticket Creation

CVE-2023-37636 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.

Learn more about our Web App Pen Testing.