CVE-2025-69828
File Upload Vulnerability in TMS Console Enables Remote Code Execution
Publication date: 2026-01-22
Last updated on: 2026-01-22
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tms_global_software | tms_management_console | 6.3.7.27386 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a File Upload vulnerability in TMS Global Software TMS Management Console version 6.3.7.27386.20250818. It allows a remote attacker to execute arbitrary code by uploading a malicious file via the Logo upload feature located at /Customer/AddEdit.
How can this vulnerability impact me? :
The vulnerability can have a severe impact as it allows remote attackers to execute arbitrary code on the affected system without any privileges or user interaction. This can lead to full system compromise, including complete loss of confidentiality, integrity, and availability of the system.