CVE-2025-59467

7.5

Ubiquiti Inc · UCRM Argentina AFIP invoices Plugin

A stored Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices plugin allows for potential privilege escalation when an administrator interacts with a malicious page.

Executive summary

A high-severity Cross-Site Scripting vulnerability in the Ubiquiti UCRM Argentina AFIP invoices plugin poses a significant risk of privilege escalation to administrative accounts.

Vulnerability

This is a Cross-Site Scripting (XSS) flaw where an attacker can execute arbitrary scripts in the context of an administrator session. The attack requires the administrator to be tricked into visiting a crafted malicious page, making it a client-side execution vector.

Business impact

The successful exploitation of this vulnerability could lead to total compromise of the affected plugin and potentially the broader UCRM environment if the injected script captures administrative credentials or performs unauthorized actions. With a CVSS score of 7.5, the vulnerability is considered High, reflecting the potential for complete impact on confidentiality, integrity, and availability once administrative privileges are escalated.

Remediation

Immediate Action: Update the UCRM Argentina AFIP invoices Plugin to version 1.3.0 or later as recommended by the vendor.

Proactive Monitoring: Review administrative audit logs for unusual configuration changes or unauthorized plugin activity that might indicate an XSS-based session hijacking attempt.

Compensating Controls: Ensure that administrators are educated on the risks of clicking untrusted links and consider utilizing a Web Application Firewall to filter potentially malicious scripts from inputs.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for privilege escalation and the high severity score, organizations using the UCRM Argentina AFIP invoices plugin should prioritize updating to version 1.3.0 immediately. If the plugin is not currently in use, it is recommended to keep it disabled, as it is disabled by default in the software distribution.

More Ubiquiti Inc CVEs

Sources