PT-2025-6893 · Internet Web Solutions · Sublime Crm

6H4Ack

+1

·

Published

2025-02-16

·

Updated

2025-02-16

·

CVE-2025-1360

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Internet Web Solutions Sublime CRM up to 20250207
Description: A problematic vulnerability was found in the HTTP POST Request Handler component of Internet Web Solutions Sublime CRM, affecting an unknown function of the file /crm/inicio.php. The manipulation of the msg to argument leads to cross-site scripting. It is possible to launch the attack remotely, and other parameters might be affected as well. The vendor was contacted about this disclosure but did not respond.
Recommendations: For Internet Web Solutions Sublime CRM up to 20250207, as a temporary workaround, consider restricting access to the msg to argument in the HTTP POST Request Handler to minimize the risk of exploitation. Avoid using the msg to argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-1360

Affected Products

Sublime Crm