Operating System Command Injection Vulnerability in AndSoft's e-TMS
CVE-2025-59738
9.3CRITICAL
What is CVE-2025-59738?
A security flaw has been identified in AndSoft's e-TMS v25.03 that enables an attacker to perform operating system command injection through a vulnerable POST request. This occurs via a specific parameter, allowing unauthorized command execution on the server. Ensuring secure coding practices and timely updates is essential to mitigate such vulnerabilities and protect sensitive data.
Affected Version(s)
e-TMS v25.03 version