Vulnerability Details
Basic Information
| Title | CVE-2025-32961 CUBA JPA Web API Vulnerable to Cross-Site Scripting (XSS) in the /download Endpoint |
|---|---|
| Type | cvelist |
| Published | 2025-04-22T17:46:00 |
| Last Seen | 2025-04-22T17:59:30 |
| CVSS Score | 6.4 (MEDIUM) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2025-32961 |
|---|---|
| CWE | CWE-79 |
| Bulletin Family | cve |
Description
The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTTP requests. Prior to version 1.1.1, the input parameter, which consists of a file path and name, can be manipulated to return…
Impact Assessment
| Base Score | 6.4 |
|---|---|
| Severity | MEDIUM |