Operating System Command Injection in AndSoft's e-TMS Software
CVE-2025-59741
9.3CRITICAL
What is CVE-2025-59741?
An operating system command injection vulnerability exists in AndSoft's e-TMS v25.03, enabling an attacker to execute arbitrary commands on the server. This is achieved by manipulating the 'm' parameter within the '/CLT/LOGINERRORFRM.ASP' endpoint through a specially crafted POST request.
Affected Version(s)
e-TMS v25.03 version