CVE-2025-5993

CRITICAL

ITCube CRM <2025.2 - Path Traversal

Title source: llm
STIX 2.1

Description

ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://cert.pl/posts/2025/07/CVE-2025-5993
Various Sources product
https://itcube.pl/modul-crm

Scores

CVSS v4 9.2
EPSS 0.0056
EPSS Percentile 42.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
ITCube Software/ITCube CRM 2023.2 - 2025.2
Published Sep 08, 2025
Tracked Since Feb 18, 2026