This plugin is disabled by default.
Affected Products:
UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)
Mitigation:
Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ui
Ui argentina Afip Invoices |
|
| CPEs | cpe:2.3:a:ui:argentina_afip_invoices:*:*:*:*:*:ucrm:*:* | |
| Vendors & Products |
Ui
Ui argentina Afip Invoices |
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ubiquiti
Ubiquiti ucrm Argentina Afip Invoices Plugin |
|
| Vendors & Products |
Ubiquiti
Ubiquiti ucrm Argentina Afip Invoices Plugin |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Mon, 05 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later. | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-01-05T20:58:05.416Z
Reserved: 2025-09-16T15:00:07.876Z
Link: CVE-2025-59467
Updated: 2026-01-05T20:58:00.745Z
Status : Analyzed
Published: 2026-01-05T17:15:45.987
Modified: 2026-02-05T21:22:19.060
Link: CVE-2025-59467
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:17:14Z