CVE-2025-13589: Otsuka Information Technology Fms
Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.
FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Affected products
- Otsuka Information Technology Fms: up to and including 20251014.10r45111
Published 2025-11-24. Last modified 2026-10-08.