Wandsoft · E-Tms · CVE-2025-59753
**Name of the Vulnerable Software and Affected Versions**
AndSoft e-TMS version 25.03
**Description**
A cross-site scripting issue exists that allows an attacker to execute JavaScript code in a user's browser. This is achieved by sending a malicious URL to a victim. The vulnerability is reflected in the `/clt/LOGINFRM BET.ASP` endpoint, specifically through the `l`, `demo`, `demo2`, `TNTLOGIN`, `UO`, and `SuppConn` parameters.
**Recommendations**
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the `l`, `demo`, `demo2`, `TNTLOGIN`, `UO`, and `SuppConn` parameters in the `/clt/LOGINFRM BET.ASP` endpoint to prevent the injection of malicious scripts.