PT-2025-17576 · Unknown · Cuba Rest Api Add-On

Lowknstvk

·

Published

2025-04-22

·

Updated

2025-04-23

·

CVE-2025-32960

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CUBA REST API add-on versions prior to 7.2.7
Description The issue allows malicious JavaScript code to be executed in the browser by manipulating the input parameter, which consists of a file path and name, to return the Content-Type header with text/html if the name part ends with .html. This requires a malicious file to be uploaded beforehand.
Recommendations For versions prior to 7.2.7, update to version 7.2.7 to resolve the issue. As a temporary workaround, consider using the workaround provided on the Jmix documentation website until the update to version 7.2.7 can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-32960
GHSA-88H5-34XW-2Q56
GHSA-X27V-F838-JH93

Affected Products

Cuba Rest Api Add-On