天下漏洞,尽知其名
MEDIUM

CVE-2026-105029 UVdesk support-center-bundle 越权访问漏洞

影响已认证客户可越权评价他人工单

AI 研判

UVdesk support-center-bundle 的 Controller/Ticket.php 中 rateTicket 动作存在不安全的直接对象引用(IDOR)漏洞。该组件在加载工单时未校验归属关系,导致已认证客户可对他人工单提交或修改满意度评分。

影响范围

UVdesk support-center-bundle

UVdesk support-center-bundle 1.1.3.3 之前的版本受影响。

漏洞详情

漏洞类型为不安全的直接对象引用(IDOR),成因是 rateTicket 动作在处理评分请求时直接使用用户传入的工单 ID 加载工单,未验证该工单是否属于当前登录客户。攻击者只需提供任意工单 ID,即可对他人拥有的工单提交或更改满意度评分。

利用条件与风险

利用前提是攻击者需具备已认证客户账号,实战中可被用于篡改他人工单的满意度数据,影响业务统计与工单评价的可信度,风险等级为中危。

修复建议

建议升级至 1.1.3.3 或更高版本;若无法立即升级,可在 rateTicket 动作中增加工单归属校验,确保仅工单所有者可进行评分操作。

原始情报

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers’ tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.