Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 19 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Compassplustechnologies
Compassplustechnologies tranzaxis |
|
| CPEs | cpe:2.3:a:compassplustechnologies:tranzaxis:3.2.41.10.26:*:*:*:*:*:*:* | |
| Vendors & Products |
Compassplustechnologies
Compassplustechnologies tranzaxis |
|
| Metrics |
cvssV3_1
|
Fri, 05 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Compassplus
Compassplus tranzaxis |
|
| Vendors & Products |
Compassplus
Compassplus tranzaxis |
Thu, 04 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges. | |
| Title | TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-05T17:50:31.047Z
Reserved: 2025-12-04T16:24:10.581Z
Link: CVE-2025-66574
Updated: 2025-12-05T17:50:17.419Z
Status : Analyzed
Published: 2025-12-04T21:16:10.250
Modified: 2025-12-19T19:43:41.877
Link: CVE-2025-66574
No data.
OpenCVE Enrichment
Updated: 2025-12-05T10:52:31Z