VYPR
Medium severity5.4NVD Advisory· Published Dec 1, 2025· Updated Jun 17, 2026

CVE-2025-64030

CVE-2025-64030

Description

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their browsers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:chinasystems:eximbills_enterprise:4.1.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:chinasystems:eximbills_enterprise:4.1.5:*:*:*:*:*:*:*
    • (no CPE)range: 4.1.5 (Built on 2020-10-30)
  • Eximbills/Enterprisecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 4.1.5 (Built on 2020-10-30)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.