Cross-Site Scripting Vulnerability in AndSoft's e-TMS Software
CVE-2025-59751
5.1MEDIUM
What is CVE-2025-59751?
A cross-site scripting (XSS) vulnerability exists in AndSoft's e-TMS v25.03 that can allow a malicious actor to execute arbitrary JavaScript in a victim's browser. This can occur when a user is tricked into clicking a malicious link that contains a specially crafted URL. The vulnerability is associated with parameters such as 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' in the '/clt/LOGINFRM_DJO.ASP' endpoint. Proper input validation and sanitization are essential to mitigate this risk and protect users from potential exploits.
Affected Version(s)
e-TMS v25.03 version