CVE-2025-59771
Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_MRK.ASP'.
Vendor
Product
CWE
Yayın Tarihi
2025-10-02 15:15:58
Güncelleme
2025-10-02 19:53:07
Source Identifier
cve-coordination@incibe.es
KEV Date Added
-