Vulnerabilities (CVE)

Filtered by vendor Tmsglobalsoft Subscribe
Filtered by product Tms Management Console
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-69612 1 Tmsglobalsoft 1 Tms Management Console 2026-02-03 N/A 6.5 MEDIUM
A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download Template" function in the profile dashboard does not neutralize directory traversal sequences (../) in the filePath parameter, allowing authenticated users to read arbitrary files, such as the server's Web.config.