ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 08 Sep 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process. | |
Title | Path Traversal in ITCube CRM | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-09-08T13:40:52.885Z
Reserved: 2025-06-11T07:34:58.422Z
Link: CVE-2025-5993

Updated: 2025-09-08T13:40:18.236Z

Status : Received
Published: 2025-09-08T11:15:31.100
Modified: 2025-09-08T11:15:31.100
Link: CVE-2025-5993

No data.

No data.