AndSoft e-TMS Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in AndSoft's e-TMS version 25.03. This issue allows an attacker to execute JavaScript in the victim's browser by sending a malicious URL. The vulnerability arises from the 'l', 'demo', 'demo2', 'TNTLOGIN', 'UO', and 'SuppConn' parameters in the '/clt/LOGINFRM_DHL.ASP' file.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute scripts in the context of the user's browser.
Remediation
Users can upgrade to AndSoft e-TMS version 25.04, where this vulnerability has been fixed. For those using version 25.03, patches are available in versions VNL 25001 and VNL 25010.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
