CVE-2025-59467

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:argentina_afip_invoices:*:*:*:*:*:ucrm:*:*

History

05 Feb 2026, 21:22

Type Values Removed Values Added
First Time Ui argentina Afip Invoices
Ui
References () https://community.ui.com/releases/Security-Advisory-Bulletin-057/6d3f2a51-22b8-47a1-9296-1e9dcd64e073 - () https://community.ui.com/releases/Security-Advisory-Bulletin-057/6d3f2a51-22b8-47a1-9296-1e9dcd64e073 - Vendor Advisory
CPE cpe:2.3:a:ui:argentina_afip_invoices:*:*:*:*:*:ucrm:*:*

Information

Published : 2026-01-05 17:15

Updated : 2026-02-05 21:22


NVD link : CVE-2025-59467

Mitre link : CVE-2025-59467

CVE.ORG link : CVE-2025-59467


JSON object : View

Products Affected

ui

  • argentina_afip_invoices
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')