Description
ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27135 | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process. |
References
History
Mon, 08 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process. | |
| Title | Path Traversal in ITCube CRM | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-09-08T13:40:52.885Z
Reserved: 2025-06-11T07:34:58.422Z
Link: CVE-2025-5993
Updated: 2025-09-08T13:40:18.236Z
Status : Deferred
Published: 2025-09-08T11:15:31.100
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5993
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD