Home

Description

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their browsers.

PUBLISHED Reserved 2025-10-27 | Published 2025-12-01 | Updated 2025-12-01 | Assigner mitre

References

chinasystems.com/whatwedo/ee

0xy37.medium.com/...eximbills-enterprise-v4-1-5-f8f5a79c4f0b

cve.org (CVE-2025-64030)

nvd.nist.gov (CVE-2025-64030)

Download JSON