Cross-Site Scripting Vulnerability in AndSoft's e-TMS Software
CVE-2025-59760

5.1MEDIUM

Key Information:

Vendor

Andsoft

Status
Vendor
CVE Published:
2 October 2025

What is CVE-2025-59760?

The cross-site scripting vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript into the user's browser. This is achieved through specially crafted URLs that exploit certain parameters like 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' in the '/clt/LOGINFRM_DHL.ASP' endpoint. When users are tricked into clicking these URLs, it could lead to unauthorized actions or data theft from their browser sessions.

Affected Version(s)

e-TMS v25.03 version

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maximilian Hildebrand (m10x.de)
.