PT-2025-17575 · Unknown · Cuba Platform

Knstvk

·

Published

2025-04-22

·

Updated

2025-04-23

·

CVE-2025-32959

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CUBA Platform versions prior to 7.2.23
Description The local file storage implementation in CUBA Platform does not restrict the size of uploaded files, allowing an attacker to upload excessively large files. This could cause the server to run out of space and return an HTTP 500 error, resulting in a denial of service.
Recommendations For versions prior to 7.2.23, update to version 7.2.23 to resolve the issue. As a temporary workaround, consider implementing file size restrictions on the local file storage implementation until the patch is applied.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32959
GHSA-F3GV-CWWH-758M
GHSA-W3MP-6VRJ-875G

Affected Products

Cuba Platform