Cross-Site Scripting Vulnerability in AndSoft's e-TMS
CVE-2025-59753
5.1MEDIUM
What is CVE-2025-59753?
The XSS vulnerability in AndSoft's e-TMS version 25.03 allows attackers to execute arbitrary JavaScript code in users' browsers. By crafting a malicious URL that exploits specific parameters, such as 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' in the '/clt/LOGINFRM_BET.ASP' file, an attacker can manipulate the victim's browser session. This incident underscores the necessity for developers to implement rigorous input validation to safeguard user data and prevent unauthorized script execution.
Affected Version(s)
e-TMS v25.03 version