Eveo URVE Smart Office Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Eveo URVE Smart Office, affecting all versions prior to 1.1.24. The issue arises in the 'report problem' feature, where an attacker with a low-privileged account can upload an SVG file containing a malicious payload. This payload is executed when a victim accesses the URL of the uploaded resource, which is available to anyone without authentication.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded malicious payloads are executed when the resource is accessed.

Remediation

Users can upgrade to URVE Smart Office version 1.1.24 or later to address this vulnerability.

Added: Oct 30, 2025, 1:17 PM
Updated: Oct 30, 2025, 3:10 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
5.0
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.