PT-2025-53688 · Advaya Softech · Gems Erp Portal

·

CVE-2025-15170

·

Published

2025-12-29

·

Updated

2025-12-29

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advaya Softech GEMS ERP Portal versions up to 2.1
Description A security issue exists in Advaya Softech GEMS ERP Portal. The issue is related to cross site scripting, occurring through manipulation of the Message argument within the Error Message Handler component. The affected file is /home.jsp?isError=true. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed.
Recommendations Versions prior to 2.1 should be updated.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15170

Affected Products

Gems Erp Portal