Vulnerability Description
Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their browsers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chinasystems | Eximbills Enterprise | 4.1.5 |
Related Weaknesses (CWE)
References
- https://0xy37.medium.com/stored-xss-in-chinasystems-eximbills-enterprise-v4-1-5-ExploitThird Party Advisory
- https://chinasystems.com/whatwedo/eeProduct
FAQ
What is CVE-2025-64030?
CVE-2025-64030 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the ...
How severe is CVE-2025-64030?
CVE-2025-64030 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64030?
Check the references section above for vendor advisories and patch information. Affected products include: Chinasystems Eximbills Enterprise.