URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.
History

Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Urve
Urve urve
Vendors & Products Urve
Urve urve

Thu, 30 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
Description URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.
Title Stored Cross-Site Scripting in URVE Smart Office
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-10-30T13:00:43.106Z

Updated: 2025-10-30T14:26:38.615Z

Reserved: 2025-09-12T09:42:32.466Z

Link: CVE-2025-10348

cve-icon Vulnrichment

Updated: 2025-10-30T14:26:31.816Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T13:15:32.500

Modified: 2025-10-30T15:03:13.440

Link: CVE-2025-10348

cve-icon Redhat

No data.