CVE 5.1 MEDIUM

Stored Cross-Site Scripting in URVE Smart Office_CVE-2025-10348

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication.

This issue was fixed in version 1.1.24.

Basic Information

ID CVE-2025-10348
Source CERT-PL
Published Oct 30, 2025 at 13:00
Modified Oct 30, 2025 at 14:26

Affected Product

Vendor Eveo
Product URVE Smart Office
Affected Versions Eveo URVE Smart Office 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.