CVE-2025-14320 PUBLISHED

XSS in Tegsoft's Online Support Application

Assigner: TR-CERT
Reserved: 09.12.2025 Published: 04.05.2026 Updated: 04.05.2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS.

This issue affects Online Support Application: from V3 through 31122025.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Tegsoft Management and Information Services Trade Limited Company
Product Online Support Application
Versions Default: unaffected
  • affected from V3 to 31122025 (incl.)

Credits

  • Selay YURDAGÜL finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS