XSS Vulnerability in AndSoft's e-TMS Software
CVE-2025-59746

6.9MEDIUM

Key Information:

Vendor

Andsoft

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-59746?

A Cross-site scripting (XSS) vulnerability exists in AndSoft's e-TMS version 25.03, which allows attackers to inject and execute arbitrary JavaScript code in the victim’s browser. This occurs through the manipulation of the 'm' parameter within the '/lib/asp/alert.asp' endpoint, enabling potential unauthorized actions under the guise of the user. Victims are tricked into clicking on malicious links that exploit this vulnerability, highlighting the critical need for proper input validation and sanitization by the vendor.

Affected Version(s)

e-TMS v25.03 version

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maximilian Hildebrand (m10x.de)
.
CVE-2025-59746 : XSS Vulnerability in AndSoft's e-TMS Software