Skip to main content

Vendor archive

andsoft CVEs

Beta · best-effort

40 CVEs tagged to vendor andsoft9 Critical, 1 High, 30 Medium, 0 Low, 0 Unrated.

CVE-2025-59749

Published Oct 2, 2025

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending t…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59748

Published Oct 2, 2025

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending t…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59747

Published Oct 2, 2025

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending t…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59746

Published Oct 2, 2025

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending t…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59745

Published Oct 2, 2025

Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cryptographically vulnerable hash algorithm and is no longer…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59744

Published Oct 2, 2025

Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only within the web root using the “docurl” parameter in “/lib/asp/DO…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59743

Published Oct 2, 2025

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59742

Published Oct 2, 2025

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59741

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59740

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59739

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59738

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59737

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59736

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59735

Published Oct 2, 2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a P…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-40 of 40 CVEsPage 2 of 2