Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andrey Moerov

#27775of 53,632
9.2Total CVSS
Vulnerabilities · 1
PT-2025-36453
9.2
2025-09-08
Itcube · Itcube Crm · CVE-2025-5993
Name of the Vulnerable Software and Affected Versions: ITCube CRM versions 2023.2 through 2025.2 Description: ITCube CRM is susceptible to a path traversal issue. An unauthenticated remote attacker can exploit the `fileName` parameter to construct payloads that enable the download of any file accessible by the web server process. Recommendations: For ITCube CRM versions 2023.2 through 2025.2, sanitize or restrict the `fileName` parameter to prevent path traversal attempts.