Cross-Site Scripting Vulnerability in AndSoft's e-TMS Software
CVE-2025-59760
5.1MEDIUM
What is CVE-2025-59760?
The cross-site scripting vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript into the user's browser. This is achieved through specially crafted URLs that exploit certain parameters like 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' in the '/clt/LOGINFRM_DHL.ASP' endpoint. When users are tricked into clicking these URLs, it could lead to unauthorized actions or data theft from their browser sessions.
Affected Version(s)
e-TMS v25.03 version