CVE-2025-71419 Overview
CVE-2025-71419 is a stored cross-site scripting (XSS) vulnerability in UVdesk core-framework versions prior to 1.1.7. The flaw resides in the createMailerConfiguration action of the SwiftMailer controller, where the configuration identifier parameter is not sanitized before being persisted and rendered. An authenticated user holding the ROLE_AGENT privilege can inject arbitrary JavaScript into the identifier field. The payload executes in the browser of any member who subsequently opens the configuration update page, enabling session theft, action forgery, or privilege abuse against helpdesk administrators. The vulnerability is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
A ROLE_AGENT attacker can persist JavaScript that executes in higher-privileged users' browsers, enabling account takeover of helpdesk administrators.
Affected Products
- UVdesk core-framework versions before 1.1.7
- UVdesk community-skeleton distributions bundling the vulnerable core-framework
- Deployments using Controller/SwiftMailer.php from v1.1.6 or earlier
Discovery Timeline
- 2026-09-21 - CVE-2025-71419 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2025-71419
Vulnerability Analysis
The vulnerability exists in the createMailerConfiguration action defined in Controller/SwiftMailer.php. When an authenticated agent submits the SwiftMailer configuration form, the id (identifier) parameter is passed directly to createConfiguration() and later stored on disk. The stored value is then rendered by the Twig template Resources/views/SwiftMailer/manageConfigurations.html.twig at line 324 without appropriate output encoding for the context in which it appears.
Because the identifier round-trips from an agent-controlled form to a persistent store and back to an administrative view, injected script executes in the browser of any member who opens the configuration page. This provides an attack path for horizontal or vertical escalation inside the helpdesk tenant, allowing exfiltration of session cookies, CSRF token replay, or forced actions on behalf of administrators.
Root Cause
The root cause is missing input validation on the id parameter combined with insufficient contextual output escaping in the management template. No allow-list constraint was enforced on identifier characters, so payloads containing HTML tags and JavaScript survived storage and reached the DOM.
Attack Vector
Exploitation requires network access to the UVdesk helpdesk interface and a valid ROLE_AGENT account. The attacker submits a crafted mailer configuration whose identifier contains a script payload. When a member, typically an administrator with higher privileges, browses the configuration update page, the payload executes in their authenticated session context.
// Security patch in Controller/SwiftMailer.php (v1.1.7)
$params['password'] = base64_encode($params['password']);
$swiftmailer = $this->swiftMailer;
if (! empty($params['id']) && ! preg_match('/^[a-zA-Z0-9_-]+$/', $params['id'])) {
$this->addFlash('warning', $this->translator->trans('Invalid ID format. Only alphanumeric characters, underscores, and hyphens are allowed.'));
return new RedirectResponse($this->generateUrl('helpdesk_member_swiftmailer_create_mailer_configuration'));
}
$swiftmailerConfiguration = $swiftmailer->createConfiguration($params['transport'], $params['id']);
Source: GitHub Core Framework Commit e5e92d1
The patch enforces an allow-list regex on the identifier and rejects any value containing characters outside a-zA-Z0-9_-.
Detection Methods for CVE-2025-71419
Indicators of Compromise
- SwiftMailer configuration identifiers containing HTML angle brackets, quotes, or the strings script, onerror, onload, or javascript:.
- Unexpected outbound requests from administrator browsers immediately after visiting /en/member/settings/swiftmailer or the configuration update page.
- New mailer configurations created by low-privilege ROLE_AGENT accounts that do not typically manage mail transport.
Detection Strategies
- Inspect the SwiftMailer configuration store (YAML or database rows) for identifier fields that fail the ^[a-zA-Z0-9_-]+$ pattern.
- Review web server access logs for POST requests to the helpdesk_member_swiftmailer_create_mailer_configuration route containing non-alphanumeric characters in the id parameter.
- Correlate agent-account creation of mailer configurations with subsequent administrator sessions loading the configuration page.
Monitoring Recommendations
- Enable audit logging on all SwiftMailer controller actions and alert when non-admin roles invoke configuration mutations.
- Monitor administrative browser sessions for anomalous XHR requests, cookie access, or DOM writes originating from the helpdesk domain.
- Track file changes under the SwiftMailer configuration directory for values written by agent-tier users.
How to Mitigate CVE-2025-71419
Immediate Actions Required
- Upgrade UVdesk core-framework to version 1.1.7 or later; community-skeleton deployments should move to release v1.1.8.
- Audit existing SwiftMailer configurations and delete any entry whose identifier does not match ^[a-zA-Z0-9_-]+$.
- Rotate administrator session cookies and reset credentials for any account that may have loaded a tampered configuration page.
Patch Information
The fix is delivered in commit e5e92d1 and shipped in core-framework release v1.1.7. The corresponding distribution is community-skeleton v1.1.8. Refer to the VulnCheck advisory for additional advisory context.
Workarounds
- If patching is delayed, restrict the ROLE_AGENT group from accessing the SwiftMailer configuration routes via reverse-proxy rules or a Symfony security firewall.
- Deploy a web application firewall rule that blocks POST bodies to the create-mailer-configuration endpoint when the id parameter contains characters outside [a-zA-Z0-9_-].
- Enforce a strict Content Security Policy that disallows inline scripts on the helpdesk administrative interface to reduce payload execution surface.
# Example Nginx rule to block non-conforming identifier values
location ~ ^/[a-z]{2}/member/settings/swiftmailer {
if ($request_method = POST) {
if ($request_body ~* "(^|&)id=[^&]*[^a-zA-Z0-9_\-%]") {
return 400;
}
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
