Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12221 | The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the browser. For a successful attack, a malicious file needs to be uploaded beforehand. This issue has been patched in version 7.2.7. A workaround is provided on the Jmix documentation website. |
Github GHSA |
GHSA-88h5-34xw-2q56 | XSS in the /files Endpoint of the Generic REST API |
Wed, 23 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the browser. For a successful attack, a malicious file needs to be uploaded beforehand. This issue has been patched in version 7.2.7. A workaround is provided on the Jmix documentation website. | |
| Title | CUBA Generic REST API Vulnerable to Cross-Site Scripting (XSS) in the /files Endpoint | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T15:59:07.985Z
Reserved: 2025-04-14T21:47:11.453Z
Link: CVE-2025-32960
Updated: 2025-04-22T19:18:12.652Z
Status : Deferred
Published: 2025-04-22T18:16:00.380
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-32960
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA