Junglewise Threat Intelligence

CVE-2025-14320: Tegsoft Online Support Application reflected XSS

CVE-2025-14320 · Severity: critical · CVSS 9.8 · Published 2026-05-04

Executive brief

Tegsoft's Online Support Application, used for managing customer service interactions, contains a critical security flaw. This vulnerability allows attackers to inject malicious scripts into the application, which could lead to the theft of sensitive session data, unauthorized access to customer support accounts, or the manipulation of web content. Because the flaw is rated as critical, it poses a significant risk to the confidentiality and integrity of the support platform.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the Tegsoft Online Support Application due to improper neutralization of user-supplied input during web page generation. The vulnerability is classified under CWE-79 and affects versions V3 through 31122025. Although typically XSS requires user interaction, the provided CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) suggests a high-impact scenario where an unauthenticated remote attacker can exploit the flaw to compromise confidentiality, integrity, and availability. Successful exploitation could allow an attacker to hijack user sessions, steal cookies, or perform actions on behalf of the user within the context of the application.

Affected products

  • Tegsoft Management and Information Services Trade Limited Company Online Support Application V3 through 31122025

Timeline

  • 2026-05-04: advisory: NVD published the vulnerability record based on TR-CERT data.

References