CVE-2025-59467
Unknown
Unknown - Not Provided
Cross-Site Scripting in UCRM AFIP Plugin Enables Privilege Escalation
Publication date: 2026-01-05
Last updated on: 2026-02-05
Assigner: HackerOne
Description
Description
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page.
This plugin is disabled by default.
Affected Products:
UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier)
Mitigation:
Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ucrm | argentina_afip_invoices_plugin | to 1.3.0 (exc) |
| ui | argentina_afip_invoices | to 1.3.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |