CVE-2025-1360 describes a problematic cross-site scripting (XSS) vulnerability in Internet Web Solutions Sublime CRM, affecting versions up to 20250207. Specifically, manipulating the 'msg_to' argument within the /crm/inicio.php file allows for remote XSS attacks. The vulnerability has a low CVSS score of 3.5, indicating a low severity. It requires user interaction and low privileges, with no impact on confidentiality or availability, and only a low impact on integrity. There is currently no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. The vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Internet Web Solutions | Sublime CRM | 20250207CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.