FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Advisories

No advisories yet.

Fixes

Solution

Update to version 20251020.18r45177 and later


Workaround

No workaround given by the vendor.

History

Mon, 24 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 03:45:00 +0000

Type Values Removed Values Added
Description FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Title Otsuka Information Technology|FMS - Reflected Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-11-24T16:04:29.829Z

Reserved: 2025-11-24T02:49:54.484Z

Link: CVE-2025-13589

cve-icon Vulnrichment

Updated: 2025-11-24T16:04:24.170Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-24T04:15:57.737

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-13589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.