Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Andrey Moerov

#29320of 56,330
9.2Total CVSS
Vulnerabilities · 1
PT-2025-36453
9.2
2025-09-08
Itcube · Itcube Crm · CVE-2025-5993
Name of the Vulnerable Software and Affected Versions: ITCube CRM versions 2023.2 through 2025.2 Description: ITCube CRM is susceptible to a path traversal issue. An unauthenticated remote attacker can exploit the `fileName` parameter to construct payloads that enable the download of any file accessible by the web server process. Recommendations: For ITCube CRM versions 2023.2 through 2025.2, sanitize or restrict the `fileName` parameter to prevent path traversal attempts.