Cross-Site Scripting Vulnerability in AndSoft e-TMS Application
CVE-2025-59772
5.1MEDIUM
What is CVE-2025-59772?
The e-TMS application from AndSoft contains a Cross-Site Scripting vulnerability that can be exploited by attackers through maliciously crafted URLs. When these URLs are accessed by users, the attacker can execute arbitrary JavaScript code within the victim's browser. This risk is associated with specific parameters including 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' found in the '/clt/LOGINFRM_SIL.ASP' endpoint, posing a significant security threat to users of the application.
Affected Version(s)
e-TMS v25.03 version