URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication.
This issue was fixed in version 1.1.24.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Urve Urve urve | |
| Vendors & Products | Urve Urve urve | 
Thu, 30 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 30 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24. | |
| Title | Stored Cross-Site Scripting in URVE Smart Office | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-10-30T13:00:43.106Z
Updated: 2025-10-30T14:26:38.615Z
Reserved: 2025-09-12T09:42:32.466Z
Link: CVE-2025-10348
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-30T14:26:31.816Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-30T13:15:32.500
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-10348
 Redhat
                        Redhat
                    No data.