GHSA-jhv5-73fw-76g2CriticalCVSS 9.8

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.

🔗 References (6)