Impact
UVdesk Community Skeleton through version 1.1.8 does not verify authentication or the installation state when handling wizard requests in the ConfigureHelpdesk controller. An attacker who can send HTTP requests to the wizard endpoints can change the database connection information and create a super‑administrator account, giving the attacker full control of the application. This flaw allows privilege escalation, enabling the attacker to create fully privileged administrative accounts. The weakness is a classic authentication bypass vulnerability (CWE-306).
Affected Systems
The affected product is UVdesk Community Skeleton version 1.1.8 or earlier. The vulnerability impacts installations that have not updated past this version, including private deployments on which the installation wizard remains exposed. The flaw resides in the ConfigureHelpdesk controller and the routes defined in the application's resources. No other known versions are affected according to the CNA data.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating critical severity. The EPSS score is listed as < 1%, implying a very low overall probability of exploitation as of the time of analysis, although the vulnerability remains potentially exploitable by anyone who can reach the wizard URLs. It is not included in the CISA KEV catalog. Attackers only need to interact with the web application’s wizard endpoints, which are typically accessible over HTTP or HTTPS without requiring prior authentication. If the sites expose these endpoints publicly, the attack can be performed remotely without any credentials. The exploit would involve posting a carefully crafted request to repoint the database and establish a new administrative account, granting unrestricted access.
OpenCVE Enrichment