Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Compassplustechnologies
Compassplustechnologies tranzaxis |
|
| CPEs | cpe:2.3:a:compassplustechnologies:tranzaxis:3.2.41.10.26:*:*:*:*:*:*:* | |
| Vendors & Products |
Compassplustechnologies
Compassplustechnologies tranzaxis |
|
| Metrics |
cvssV3_1
|
Fri, 05 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Compassplus
Compassplus tranzaxis |
|
| Vendors & Products |
Compassplus
Compassplus tranzaxis |
Thu, 04 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges. | |
| Title | TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:09:51.960Z
Reserved: 2025-12-04T16:24:10.581Z
Link: CVE-2025-66574
Updated: 2025-12-05T17:50:17.419Z
Status : Analyzed
Published: 2025-12-04T21:16:10.250
Modified: 2025-12-19T19:43:41.877
Link: CVE-2025-66574
No data.
OpenCVE Enrichment
Updated: 2026-04-27T22:45:15Z