Impact
UVdesk core‑framework versions prior to 1.1.7 expose an authorization bypass in the saved reply endpoint. Authenticated agents with the ROLE_AGENT permission can enumerate saved reply identifiers and retrieve content that is ostensibly restricted to other support groups or teams. The ability to read these replies effectively lifts the intended access controls, allowing agents to access information they should not see. The vulnerability is a classic example of improper authorization enforcement, as indicated by its CWE-639 classification.
Affected Systems
The vulnerability affects the UVdesk community skeleton and core framework products, specifically all releases before 1.1.7. Users deploying version 1.1.6 or earlier of the core framework and community skeleton are at risk. Patch version 1.1.7 or later removes the flaw.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the medium severity range, and the EPSS score is not available, indicating no publicly known prevalence at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploit requires an authenticated agent account with ROLE_AGENT; therefore, attack is likely confined to environments where such credentials are already available or have been compromised. An attacker could enumerate all saved reply IDs through the endpoint and harvest content across support groups, thereby breaching confidentiality of group‑specific communications.
OpenCVE Enrichment