XSS Vulnerability in AndSoft's e-TMS Software
CVE-2025-59746
6.9MEDIUM
What is CVE-2025-59746?
A Cross-site scripting (XSS) vulnerability exists in AndSoft's e-TMS version 25.03, which allows attackers to inject and execute arbitrary JavaScript code in the victim’s browser. This occurs through the manipulation of the 'm' parameter within the '/lib/asp/alert.asp' endpoint, enabling potential unauthorized actions under the guise of the user. Victims are tricked into clicking on malicious links that exploit this vulnerability, highlighting the critical need for proper input validation and sanitization by the vendor.
Affected Version(s)
e-TMS v25.03 version