CNNVD-202510-330 Information
Oct 02, 2025
cve
CNNVD ID
CNNVD-202510-330
Related CVE
- CNNVD Published: 2025-10-02
Description (Chinese)
AndSoft e-TMS是西班牙AndSoft公司的一款物流管理软件。 AndSoft e-TMS v25.03版本存在SQL注入漏洞,该漏洞源于对文件/inc/login/TRACK_REQUESTFRMSQL.ASP中参数USRMAIL的错误操作,可能导致SQL注入攻击。
Description (English)
AndSoft e-TMS is a logistics management software for AndSoft in Spain. AndSoft e-TMS v25.03 has an injection loophole in SQL, which is the result of a mishandling of the parameter USRMAIL in document/inc/login/TRACK REQUESTRMSQL.ASP, which may lead to an attack on SQL injection.
Hazard Level
Low
Vulnerability Type
SQL注入
Affected Vendor
AndSoft
Published
2025-10-02
Last Modified
2026-02-24
References
Patch
https://andsoft.es/es/solucio-1/menu-1/caracteristicas.html
Share on: