CVE 7.5 HIGH

CVE-2025-59467_CVE-2025-59467

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page.

This plugin is disabled by default.


Affected Products:
UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)



Mitigation:
Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.

Basic Information

ID CVE-2025-59467
Source hackerone
Published Jan 5, 2026 at 16:47

Affected Product

Vendor Ubiquiti Inc
Product UCRM Argentina AFIP invoices Plugin
Affected Versions Ubiquiti Inc UCRM Argentina AFIP invoices Plugin 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.