XSS Vulnerability in AndSoft's e-TMS Product
CVE-2025-59764
5.1MEDIUM
What is CVE-2025-59764?
A cross-site scripting (XSS) vulnerability exists in AndSoft's e-TMS v25.03, allowing attackers to execute arbitrary JavaScript in the web browser of users via malicious URLs. The vulnerability is linked to multiple parameters such as 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' within the '/clt/LOGINFRM_FCC.ASP' endpoint, potentially compromising user data and session security.
Affected Version(s)
e-TMS v25.03 version