China Systems Eximbills Enterprise Authenticated Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in China Systems Eximbills Enterprise version 4.1.5, built on October 30, 2020. The issue arises in the web interface's template management feature, specifically through the 'TMPL_INFO' parameter via the '/EximBillWeb/servlets/WSTrxManager' endpoint. This vulnerability allows authenticated regular users to inject unsanitized JavaScript, which is then executed in the browsers of other users who access the affected template.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the template.

Reproduction

To reproduce this vulnerability, log into the application as a regular user. Navigate to 'Static Data' > 'Credit Officer' > 'Edit Gtee Commission' and click the 'Template' button. Intercept the request using a proxy tool like Burp Suite. Locate the 'TMPL_INFO' parameter and insert a payload, such as an audio tag with an 'onerror' event, to execute a script. Once the template is saved, the payload will be executed whenever the template is accessed, demonstrating the stored XSS vulnerability.

Added: Dec 1, 2025, 3:19 PM
Updated: Dec 1, 2025, 8:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.6
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.