📦 E Tms

by Andsoft

🔍 What is E Tms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59741

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows unauthenticated attackers to execute arbitrary operating system commands on the server by sending a specially c...

CVE-2025-59742

CRITICAL CVSS 9.8 Oct 2, 2025

This SQL injection vulnerability in AndSoft's e-TMS v25.03 allows attackers to execute arbitrary SQL commands via the USRMAIL parameter in login forms. Attackers can retrieve, modify, or delete databa...

CVE-2025-59743

CRITICAL CVSS 9.8 Oct 2, 2025

A critical SQL injection vulnerability in AndSoft's e-TMS v25.03 allows attackers to manipulate database operations by exploiting the 'SessionID' cookie in connection scripts. This affects all systems...

CVE-2025-59735

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management system. Attackers can execute arbitrary operating system commands on the server by sending specially cra...

CVE-2025-59736

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows attackers to execute arbitrary operating system commands on the server by sending a specially crafted POST requ...

CVE-2025-59737

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management system. Attackers can execute arbitrary operating system commands on the server by sending a specially c...

CVE-2025-59738

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows unauthenticated attackers to execute arbitrary operating system commands on the server via a POST request to '/...

CVE-2025-59739

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management software that allows unauthenticated attackers to execute arbitrary operating system commands on the ser...

CVE-2025-59740

CRITICAL CVSS 9.8 Oct 2, 2025

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management software that allows unauthenticated attackers to execute arbitrary operating system commands on the ser...

CVE-2025-59745

HIGH CVSS 7.5 Oct 2, 2025

This vulnerability in AndSoft's e-TMS v25.03 uses the MD5 hash algorithm for password encryption, which is cryptographically broken and vulnerable to collision attacks. Attackers could potentially cra...

CVE-2025-59744

HIGH CVSS 7.5 Oct 2, 2025

This path traversal vulnerability in AndSoft's e-TMS v25.03 allows attackers to access files within the web root directory by manipulating the 'docurl' parameter in '/lib/asp/DOCSAVEASASP.ASP'. Organi...

CVE-2025-59771

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing the 'l, demo, demo2, TNTLOGIN, UO and S...

CVE-2025-59772

MEDIUM CVSS 6.1 Oct 2, 2025

This is a reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS version 25.03 that allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking ...

CVE-2025-59774

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript via specially crafted URLs containing malicious parameters. When victi...

CVE-2025-59773

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript via specially crafted URLs targeting specific parameters. When victims...

CVE-2025-59765

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs. When victims click these links, the attacker can ...

CVE-2025-59766

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript via specially crafted URLs containing malicious parameters. When victi...

CVE-2025-59767

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing the 'l, demo, demo2, TNTLOGIN, UO and S...

CVE-2025-59768

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing malicious parameters. When victims clic...

CVE-2025-59769

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing the 'l, demo, demo2, TNTLOGIN, UO and S...

CVE-2025-59770

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs. When victims click these links, the attacker can ...

CVE-2025-59758

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing certain parameters. When victims click ...

CVE-2025-59759

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing parameters like 'l', 'demo', 'demo2', '...

CVE-2025-59760

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs. When victims click these links, the attacker can ...

CVE-2025-59761

MEDIUM CVSS 6.1 Oct 2, 2025

This is a reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 that allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking special...

CVE-2025-59762

MEDIUM CVSS 6.1 Oct 2, 2025

This is a reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 that allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking special...

CVE-2025-59763

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing malicious parameters. When victims clic...

CVE-2025-59764

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing malicious parameters. When victims clic...

CVE-2025-59751

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript via specially crafted URLs containing the 'l, demo, demo2, TNTLOGIN, U...

CVE-2025-59752

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs. When victims click these links, the attacker can ...

CVE-2025-59753

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing malicious parameters. When victims clic...

CVE-2025-59754

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to inject malicious JavaScript via specially crafted URLs containing the 'l, demo, demo2, TNTLOGIN, UO and S...

CVE-2025-59755

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to execute malicious JavaScript in victims' browsers by tricking them into visiting specially crafted...

CVE-2025-59756

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to execute arbitrary JavaScript in victims' browsers by tricking them into clicking malicious URLs co...

CVE-2025-59757

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to execute arbitrary JavaScript in victims' browsers by tricking them into clicking malicious URLs containin...

CVE-2025-59746

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking a specially crafted URL....

CVE-2025-59747

MEDIUM CVSS 6.1 Oct 2, 2025

This is a reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 that allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking a speci...

CVE-2025-59748

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS allows attackers to execute arbitrary JavaScript in victims' browsers by tricking them into clicking malicious URLs containin...

CVE-2025-59749

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to inject malicious JavaScript via the 'l' parameter in the TRACK_REQUEST.ASP endpoint. When victims ...

CVE-2025-59750

MEDIUM CVSS 6.1 Oct 2, 2025

This reflected cross-site scripting (XSS) vulnerability in AndSoft's e-TMS v25.03 allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking specially crafted...