AndSoft e-TMS Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in AndSoft's e-TMS version 25.03. This issue allows an attacker to execute JavaScript in the context of the victim's browser by sending a malicious URL. The vulnerability arises from the 'm' parameter in the '/lib/asp/alert.asp' file.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute scripts in the user's browser session.

Remediation

Users can upgrade to AndSoft e-TMS versions VNL 25001 or VNL 25010, both released in January 2025, to address this vulnerability. As of version 25.04, these vulnerabilities have been completely fixed.

Added: Oct 2, 2025, 3:35 PM
Updated: Oct 2, 2025, 3:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.