CVE-2025-10348
Last modified
CVE-2025-10348 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-10348?
How severe is CVE-2025-10348?
How do I fix CVE-2025-10348?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-10341HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10342HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10343HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10344HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10345HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10346HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-1035Improper Limitation of a Pathname to a Restricted Directory …5.7
- CVE-2025-10350SQL Injection vulnerability in "imageserver" module when pro…8.8
- CVE-2025-10351SQL injection vulnerability based on the melis-cms module of…9.3
- CVE-2025-10352Vulnerability in the melis-core module of Melis Technology's…9.3
- CVE-2025-10353File upload leading to remote code execution (RCE) in the “m…9.3
- CVE-2025-10354Cross-Site Scripting (XSS) vulnerability reflected in Semant…5.1
Are you affected by CVE-2025-10348?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
