{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-15170","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-12-27T23:23:04.593Z","datePublished":"2025-12-29T03:32:07.618Z","dateUpdated":"2025-12-29T14:40:15.648Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-12-29T07:31:44.070Z"},"title":"Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"Advaya Softech","product":"GEMS ERP Portal","versions":[{"version":"2.0","status":"affected"},{"version":"2.1","status":"affected"}],"modules":["Error Message Handler"]}],"descriptions":[{"lang":"en","value":"A security vulnerability has been detected in Advaya Softech GEMS ERP Portal up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of the component Error Message Handler. The manipulation of the argument Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2025-12-27T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-12-28T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-12-29T08:33:43.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Syansec","type":"finder"},{"lang":"en","value":"syan (VulDB User)","type":"reporter"},{"lang":"en","value":"syan (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.338550","name":"VDB-338550 | Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.338550","name":"VDB-338550 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.717590","name":"Submit #717590 | Advaya Softech GEMS ERP Portal 2.1 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://syansec.in/video_poc/cve_2025.mp4","tags":["exploit"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-12-29T14:40:08.553806Z","id":"CVE-2025-15170","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-12-29T14:40:15.648Z"}}]}}