{"id":"CVE-2025-10348","title":"URVE Smart Office is vulnerable to Stored XSS in report problem functionality","summary":"URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the up…","severity":"none","cwe":["CWE-79"],"published":"2025-10-30","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-10348","references":[{"url":"https://cert.pl/posts/2025/10/CVE-2025-10348","label":"cvd@cert.pl"},{"url":"https://smartoffice.expert/","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.00353,"epssPercentile":0.2693,"ingestedAt":"2026-10-08T10:28:19.130Z","slug":"CVE-2025-10348","body":"## Overview\n\nURVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication.\n\nThis issue was fixed in version 1.1.24.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}