Operating System Command Injection in AndSoft's e-TMS Product
CVE-2025-59735
9.3CRITICAL
What is CVE-2025-59735?
An operating system command injection vulnerability exists in AndSoft's e-TMS v25.03, allowing attackers to execute arbitrary operating system commands on the server. By crafting a malicious POST request, an attacker can manipulate parameters in the web application, particularly a parameter identified as 'm' in the '/clt/LOGINFRM.ASP' endpoint, compromising the integrity and security of the server.
Affected Version(s)
e-TMS v25.03 version