Cross-Site Scripting Vulnerability in AndSoft e-TMS
CVE-2025-59758
5.1MEDIUM
What is CVE-2025-59758?
A reflected Cross-Site Scripting (XSS) vulnerability exists in AndSoft's e-TMS v25.03. This security flaw allows attackers to execute arbitrary JavaScript code within the context of a user's web browser by crafting a malicious URL that exploits the identified parameters such as 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' in the '/clt/LOGINFRM_CYLOG.ASP' file. Users visiting the malicious link can unknowingly expose sensitive information or suffer other malicious consequences.
Affected Version(s)
e-TMS v25.03 version