CVE-2025-59467 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator…
High CVSS: 7.5

CVE-2025-59467

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page.

This plugin is disabled by default.


Affected Products:
UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)



Mitigation:
Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
Vendor
Ui
Product
Argentina Afip Invoices
CWE
CWE-79
Yayın Tarihi
2026-01-05 17:15:45
Güncelleme
2026-02-05 21:22:19
Source Identifier
support@hackerone.com
KEV Date Added
-

Kategoriler

Referanslar