Security Advisory

CVE-2025-59467

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-05 16:47:38
Last updated 2026-01-05 20:58:05
Assigner hackerone
State PUBLISHED

Description

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.