VYPR

support-center-bundle

by Uvdesk

CVEs (1)

  • CVE-2026-105029MedOct 3, 2026
    risk 0.21cvss 4.3epss —

    UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are…