Security Advisory

CVE-2023-0325

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-04-04 00:00:00
Last updated 2025-02-13 16:22:05
Assigner Fluid Attacks
CVSS score not scored
State PUBLISHED

Description

Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.