CVE-2025-59467

🟡 Monitoruj

Luka XSS w wtyczce UCRM Argentina AFIP invoices pozwala na eskalację uprawnień przez oszukańcze strony.

CVSS
7.5
EPSS
0.3%
Exploit
none
Vendor
ui
Opis źródłowy (NVD)

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.

privilege-escalation xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-01-05 17:15:45 UTC
Ostatnia modyfikacja (NVD)2026-10-07 10:10:00 UTC
Referencje