PT-2025-49150 · Tranzaxis · Tranzaxis

Ababank Redteam

·

Published

2025-12-04

·

Updated

2025-12-19

·

CVE-2025-66574

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TranzAxis version 3.2.41.10.26
Description Authenticated users can inject cross-site scripting through the Open Object in Tree API endpoint. Successful exploitation may allow attackers to steal session cookies and potentially escalate privileges. The vulnerable parameter is not specified.
Recommendations Apply updates to address the issue in TranzAxis version 3.2.41.10.26.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66574

Affected Products

Tranzaxis