Cross-Site Scripting Flaw in AndSoft's e-TMS Software
CVE-2025-59747

6.9MEDIUM

Key Information:

Vendor

Andsoft

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-59747?

A cross-site scripting vulnerability has been identified in AndSoft's e-TMS v25.03, allowing potential attackers to inject and execute malicious JavaScript code in a victim's web browser. This exploitation occurs through a specially crafted URL, exploiting the 'l' parameter in the reset password function located at '/clt/resetPassword.asp'. Users interacting with this URL may inadvertently expose their sensitive information or credentials, making it imperative for organizations using this software to implement necessary security measures.

Affected Version(s)

e-TMS v25.03 version

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maximilian Hildebrand (m10x.de)
.
CVE-2025-59747 : Cross-Site Scripting Flaw in AndSoft's e-TMS Software