PT-2025-17576 · Unknown · Cuba Rest Api Add-On
Lowknstvk
·
Published
2025-04-22
·
Updated
2025-04-23
·
CVE-2025-32960
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CUBA REST API add-on versions prior to 7.2.7
Description
The issue allows malicious JavaScript code to be executed in the browser by manipulating the input parameter, which consists of a file path and name, to return the Content-Type header with text/html if the name part ends with .html. This requires a malicious file to be uploaded beforehand.
Recommendations
For versions prior to 7.2.7, update to version 7.2.7 to resolve the issue.
As a temporary workaround, consider using the workaround provided on the Jmix documentation website until the update to version 7.2.7 can be applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cuba Rest Api Add-On