CVE-2025-66574: Compassplustechnologies Tranzaxis
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
Affected products
- Compassplustechnologies Tranzaxis: version 3.2.41.10.26 only
Published 2025-12-04. Last modified 2026-06-17.