CNNVD-202510-331 Information

CNNVD ID

CNNVD-202510-331

CVE-2025-59741

  • CNNVD Published: 2025-10-02

Description (Chinese)

AndSoft e-TMS是西班牙AndSoft公司的一款物流管理软件。 AndSoft e-TMS v25.03版本存在命令注入漏洞,该漏洞源于对文件/CLT/LOGINERRORFRM.ASP中参数m的错误操作,可能导致操作系统命令注入攻击。

Description (English)

AndSoft e-TMS is a logistics management software for AndSoft in Spain. AndSoft e-TMS v25.03 has a command-injecting loophole that stems from an error in the operation of parameter m in document/CLT/LOGINERROFRRM.ASP, which may result in an operational system command-injecting attack.

Hazard Level

Low

Vulnerability Type

命令注入

Affected Vendor

AndSoft

Published

2025-10-02

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/update-24092025-multiple-vulnerabilities-andsofts-e-tms

Patch

https://andsoft.es/es/solucio-1/menu-1/caracteristicas.html

Share on: