Cross-Site Scripting Vulnerability in AndSoft e-TMS Software
CVE-2025-59773
5.1MEDIUM
What is CVE-2025-59773?
A Cross-Site Scripting (XSS) vulnerability exists in AndSoft's e-TMS version 25.03. This flaw allows attackers to inject and execute malicious JavaScript code in the browsers of unsuspecting users via manipulated URLs. The vulnerability is triggered through several parameters such as 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' within the '/clt/LOGINFRM_TP.ASP' endpoint, potentially compromising user data and threatening application integrity.
Affected Version(s)
e-TMS v25.03 version