Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:chinasystems:eximbills_enterprise:4.1.5:*:*:*:*:*:*:* |
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chinasystems
Chinasystems eximbills Enterprise |
|
| Vendors & Products |
Chinasystems
Chinasystems eximbills Enterprise |
Mon, 01 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 01 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their browsers. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-01T19:52:31.811Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64030
Updated: 2025-12-01T19:31:45.498Z
Status : Analyzed
Published: 2025-12-01T15:15:52.143
Modified: 2025-12-29T15:01:28.010
Link: CVE-2025-64030
No data.
OpenCVE Enrichment
Updated: 2025-12-02T12:15:29Z