PT-2025-36453 · Itcube · Itcube Crm

·

CVE-2025-5993

·

Published

2025-09-08

·

Updated

2025-09-08

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: ITCube CRM versions 2023.2 through 2025.2
Description: ITCube CRM is susceptible to a path traversal issue. An unauthenticated remote attacker can exploit the fileName parameter to construct payloads that enable the download of any file accessible by the web server process.
Recommendations: For ITCube CRM versions 2023.2 through 2025.2, sanitize or restrict the fileName parameter to prevent path traversal attempts.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-5993

Affected Products

Itcube Crm