PT-2025-40824 · Vanderlande · Vanderlande Baggage 360
Yasserreed
·
Published
2025-10-05
·
Updated
2025-10-06
·
CVE-2025-11308
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Vanderlande Baggage 360 version 7.0.0
Description
An issue exists in the processing of files within Vanderlande Baggage 360. Manipulation of the
Message argument in the /api-addons/v1/messages API endpoint can lead to cross site scripting. This attack can be performed remotely. The exploit is publicly available.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vanderlande Baggage 360