8.8
CVSSv3

CVE-2023-0265

Published: 04/04/2023 Updated: 11/04/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Uvdesk version 1.1.1 allows an authenticated remote malicious user to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uvdesk community-skeleton 1.1.1