Vulnerability Description
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0 and earlier) Mitigation: Update UCRM Argentina AFIP invoices Plugin to Version 1.3.0 or later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Argentina Afip Invoices | < 1.3.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-59467?
CVE-2025-59467 is a vulnerability with a CVSS score of 7.5 (HIGH). A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malic...
How severe is CVE-2025-59467?
CVE-2025-59467 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59467?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Argentina Afip Invoices.