CVE ID | CVE-2025-5993 |
Publication date | 08 September 2025 |
Vendor | ITCube Software |
Product | ITCube CRM |
Vulnerable versions | From 2023.2 through 2025.2 |
Vulnerability type (CWE) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in ITCube CRM software and participated in coordination of its disclosure.
The vulnerability CVE-2025-5993: ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName
and construct payloads that allow to download any file accessible by the the web server process.
Credits
We thank Andrey Moerov from Possehl Secure GmbH for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.