PT-2025-49150 · Tranzaxis · Tranzaxis
Ababank Redteam
·
Published
2025-12-04
·
Updated
2025-12-19
·
CVE-2025-66574
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TranzAxis version 3.2.41.10.26
Description
Authenticated users can inject cross-site scripting through the
Open Object in Tree API endpoint. Successful exploitation may allow attackers to steal session cookies and potentially escalate privileges. The vulnerable parameter is not specified.Recommendations
Apply updates to address the issue in TranzAxis version 3.2.41.10.26.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tranzaxis