PT-2025-17577 · Cuba Jpa · Cuba Jpa

Knstvk

·

Published

2025-04-22

·

Updated

2025-04-22

·

CVE-2025-32961

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cuba JPA versions prior to 1.1.1
Description The Cuba JPA web API allows loading and saving entities defined in the application data model through simple HTTP requests. Prior to version 1.1.1, the input parameter, which includes a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the browser. For a successful attack, a malicious file needs to be uploaded beforehand.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 to resolve the issue. As a temporary workaround, consider using the workaround provided on the Jmix documentation website until the update to version 1.1.1 can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-32961
GHSA-HG25-W3VG-7279

Affected Products

Cuba Jpa