ABABANK REDTEAM

1 exploit Active since Dec 2025
CVE-2025-66574 EXPLOITDB MEDIUM text WORKING POC
TranzAxis 3.2.41.10.26 - Authenticated Stored Cross-Site Scripting via Open Object in Tree Endpoint
TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
CVSS 5.4