Impact
UVdesk support‑center‑bundle before version 1.1.3.3 contains an insecure direct object reference that allows an authenticated customer to submit or change satisfaction ratings on tickets that do not belong to them. The rateTicket action loads arbitrary ticket identifiers without verifying ownership, meaning a user can arbitrarily elevate or lower the rating of another user’s ticket. This flaw can distort business metrics, undermine the integrity of the support service, and potentially skew revenue reporting.
Affected Systems
The vulnerability is present in the uvdesk community‑skeleton package and its support‑center‑bundle component. Any deployment using these components prior to the 1.1.3.3 release is susceptible; later releases include an ownership check that removes the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity data‑integrity weakness. EPSS data is not available, so the likelihood of active exploitation cannot be quantified from publicly available metrics, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread attacks yet. The attack requires an authenticated user and consists of sending a request to the rateTicket endpoint with a ticket identifier that belongs to another customer. No privilege escalation or remote code execution is possible; the impact is limited to the integrity of ticket ratings and the downstream processes that rely on them.
OpenCVE Enrichment