Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27135 | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 08 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process. | |
| Title | Path Traversal in ITCube CRM | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-09-08T13:40:52.885Z
Reserved: 2025-06-11T07:34:58.422Z
Link: CVE-2025-5993
Updated: 2025-09-08T13:40:18.236Z
Status : Awaiting Analysis
Published: 2025-09-08T11:15:31.100
Modified: 2025-09-08T16:25:38.810
Link: CVE-2025-5993
No data.
OpenCVE Enrichment
No data.
EUVD