URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication.
This issue was fixed in version 1.1.24.
CVSS
No CVSS.
References
Configurations
No configuration.
History
30 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 13:15
Updated : 2025-10-30 15:03
NVD link : CVE-2025-10348
Mitre link : CVE-2025-10348
CVE.ORG link : CVE-2025-10348
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
