CNNVD-202510-329 Information

CNNVD ID

CNNVD-202510-329

CVE-2025-59743

  • CNNVD Published: 2025-10-02

Description (Chinese)

AndSoft e-TMS是西班牙AndSoft公司的一款物流管理软件。 AndSoft e-TMS 25.03版本存在SQL注入漏洞,该漏洞源于对文件/inc/connect/CONNECTION.ASP中SessionID cookie参数的错误操作,可能导致SQL注入攻击。

Description (English)

AndSoft e-TMS is a logistics management software for AndSoft in Spain. AndSoft e-TMS 25.03 has an injection loophole in SQL, which stems from the erroneous operation of the SsessionID cookie parameter in document /inc/contract/CONNECTION.ASP, which may lead to an attack on SQL injection.

Hazard Level

Low

Vulnerability Type

SQL注入

Affected Vendor

AndSoft

Published

2025-10-02

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/update-24092025-multiple-vulnerabilities-andsofts-e-tms

Patch

https://andsoft.es/es/solucio-1/menu-1/caracteristicas.html

Share on: