CVE-2025-14320Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS. This issue affects Online Support Application: from V3 through 31122025.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-04: 2Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-04: 205-04
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-14320 — CVSS 9.8/10 ██████████ Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/NFHAtdE1UE

    Post summary

    The tweet announces CVE‑2025‑14320, a critical XSS vulnerability in Tegsoft, provides a CVSS score, and urges applying the available patch.

    100001.0K
    26 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-14320 Reflected Cross-Site Scripting in Tegsoft Online Support Application V3 Through 31122025 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-14320

    Post summary

    The post announces a new reflected XSS vulnerability (CVE‑2025‑14320) in Tegsoft Online Support Application V3, without indicating exploitation, patches, or PoC details.

    00000487
    4.0K followersView on X

Explore more