CVE-2025-59743 PUBLISHED

Multiple vulnerabilities in AndSoft's e-TMS

Assigner: INCIBE
Reserved: 19.09.2025 Published: 02.10.2025 Updated: 02.10.2025

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The relationship between parameter and assigned identifier is a 'SessionID' cookie in '/inc/connect/CONNECTION.ASP'.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor AndSoft
Product e-TMS
Versions Default: unaffected
  • Version v25.03 version is affected

Solutions

The vulnerability has been resolved in patches e-TMS VNL 25001 and VNL 25010.

Credits

  • Maximilian Hildebrand (m10x.de) finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE