CVE-2025-71420 Overview
CVE-2025-71420 is an authorization bypass vulnerability in the UVdesk core-framework help desk platform prior to version 1.1.7. The flaw resides in the saved reply endpoint, which fails to validate whether the requesting agent belongs to the support group or team that owns a given saved reply. Authenticated users holding the ROLE_AGENT role can enumerate saved reply identifiers and read reply content restricted to other groups. The weakness is classified as [CWE-639] Authorization Bypass Through User-Controlled Key, a form of insecure direct object reference (IDOR).
Critical Impact
Any authenticated agent can read saved reply content reserved for support groups and teams they do not belong to, exposing internal templates and potentially sensitive business communication.
Affected Products
- UVdesk core-framework versions prior to 1.1.7
- UVdesk community-skeleton deployments packaging vulnerable core-framework releases (fixed distribution in v1.1.8)
- Self-hosted UVdesk help desk instances running v1.1.6 and earlier
Discovery Timeline
- 2026-09-21 - CVE-2025-71420 published to NVD
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2025-71420
Vulnerability Analysis
UVdesk exposes an XHR endpoint that returns the content of a saved reply based on an id query parameter supplied by the client. In vulnerable releases, the controller passes the identifier directly to TicketService::getSavedReplyContent() without verifying that the authenticated agent belongs to the group or team associated with the requested reply. Because saved replies are typically scoped to specific support groups, this omission collapses the intended access boundary.
An authenticated agent can iterate numeric saved reply identifiers and retrieve the body of each one. The returned content may include internal response templates, escalation language, credentials embedded in canned responses, or customer-facing text intended only for privileged teams. Confidentiality of business communication is affected, while integrity and availability of the ticketing data remain unchanged.
Root Cause
The root cause is missing authorization enforcement in Controller/TicketXHR.php and Services/TicketService.php at the saved reply retrieval path. The vulnerable code path in TicketXHR.php (v1.1.6) and TicketService.php (v1.1.6) trusts the client-supplied id and returns content without cross-referencing the agent's group and team membership against the reply's ownership.
Attack Vector
An attacker must authenticate to the UVdesk instance with ROLE_AGENT. From an authenticated session, the attacker issues XHR GET requests to the saved reply endpoint, varying the id parameter to enumerate replies owned by other groups. The server returns the reply content in JSON regardless of the agent's group membership.
// Patch excerpt: Controller/TicketXHR.php
$data = $request->query->all();
if ($request->isXmlHttpRequest()) {
- $json['message'] = $this->ticketService->getSavedReplyContent($data['id'], $data['ticketId']);
+ try {
+ $json['message'] = $this->ticketService->getSavedReplyContent($data['id'], $data['ticketId']);
+ } catch (\Exception $e) {
+ $json['alertClass'] = 'danger';
+ $json['alertMessage'] = $e->getMessage();
+
+ return new Response(json_encode($json), 400, ['Content-Type' => 'application/json']);
+ }
}
$response = new Response(json_encode($json));
// Source: https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d
The patched controller now catches exceptions raised by the underlying service, which enforces the authorization check and rejects unauthorized identifiers with an HTTP 400 response.
Detection Methods for CVE-2025-71420
Indicators of Compromise
- Sequential or high-volume XHR GET requests to the saved reply endpoint with incrementing id parameters from a single authenticated agent session.
- Agents retrieving saved reply content whose owning group or team does not match the agent's assigned membership in the UVdesk database.
- Unusual spikes in JSON responses containing message payloads from the ticket XHR controller during a short time window.
Detection Strategies
- Enable and review UVdesk web server access logs for repeated requests to the saved reply endpoint, correlating request id values against the authenticated user's group membership.
- Deploy a web application firewall rule that rate-limits saved reply reads per agent session and alerts on enumeration patterns.
- Query the application database to compare savedReply.supportGroup and supportTeam ownership against the requesting agent's memberships recorded in the audit trail.
Monitoring Recommendations
- Forward UVdesk application and web server logs to a centralized log platform and build dashboards for saved reply endpoint activity per user.
- Alert on any single agent account issuing more than a defined threshold of saved reply requests within a rolling window.
- Monitor for HTTP 200 responses to saved reply requests originating from agent accounts that historically do not use saved replies.
How to Mitigate CVE-2025-71420
Immediate Actions Required
- Upgrade UVdesk core-framework to version 1.1.7 or later, or deploy community-skeletonv1.1.8, which packages the fixed framework.
- Audit saved reply access logs since deployment to identify agent accounts that enumerated identifiers outside their group scope.
- Rotate or redact any sensitive content, credentials, or customer data embedded in saved replies that may have been exposed.
Patch Information
The fix is delivered in commit de0422869708 and released in core-framework v1.1.7. The patch wraps the getSavedReplyContent() call in exception handling so that authorization failures surfaced by TicketService are returned as HTTP 400 responses instead of leaking content. See the VulnCheck advisory for additional context.
Workarounds
- Restrict ROLE_AGENT accounts to trusted personnel and revoke access for shared or contractor accounts until the upgrade is applied.
- Temporarily disable the saved reply feature at the reverse proxy by blocking requests to the affected XHR endpoint if patching is not immediately feasible.
- Move sensitive template content out of saved replies until the environment is upgraded to a fixed release.
# Example nginx rule to block the vulnerable endpoint until patched
location ~* /ticket/xhr/savedreply {
return 403;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
