rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3

CVE-2026-105029

UVdesk support-center-bundle versions prior to 1.1.3.3 allow authenticated customers to rate tickets belonging to other customers. The vulne

Overview

UVdesk support-center-bundle versions prior to 1.1.3.3 allow authenticated customers to rate tickets belonging to other customers. The vulnerability arises from an insecure direct object reference in the rateTicket action. It can lead to manipulation of customer satisfaction data.

Description

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.

Impact

The integrity of customer satisfaction ratings is compromised, enabling malicious users to alter or fabricate feedback. This can distort support metrics and erode trust in the platform. Confidentiality and availability are not directly affected.

Remediation

Apply the official patch to upgrade to version 1.1.3.3 or later. Verify that the rateTicket endpoint performs an ownership check before processing the rating. If an upgrade is not immediately possible, restrict access to the rating action to the ticket owner only and monitor for anomalous rating activity.

Risk context

The CVSS v3 score of 4.3 and v4 score of 5.3 classify this as medium severity. With no EPSS data available, the risk is considered moderate and warrants timely remediation but does not pose an immediate critical threat.

Affected products

  • UVdesk support-center-bundle

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
5.3
EPSS
—

IDOR UVdesk ticket rating customer data medium severity

← All CVEs