PT-2025-40824 · Vanderlande · Vanderlande Baggage 360

Yasserreed

·

Published

2025-10-05

·

Updated

2025-10-06

·

CVE-2025-11308

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Vanderlande Baggage 360 version 7.0.0
Description An issue exists in the processing of files within Vanderlande Baggage 360. Manipulation of the Message argument in the /api-addons/v1/messages API endpoint can lead to cross site scripting. This attack can be performed remotely. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11308

Affected Products

Vanderlande Baggage 360