CVE-2025-66574 Overview
CVE-2025-66574 is a stored cross-site scripting (XSS) vulnerability in Compass Plus Technologies TranzAxis version 3.2.41.10.26. The flaw resides in the Open Object in Tree endpoint, which fails to sanitize user-supplied input before rendering it in the application interface. Authenticated users can inject malicious JavaScript that executes in the context of other users' browser sessions. Successful exploitation enables session cookie theft and can lead to privilege escalation within the TranzAxis payment processing platform. The issue is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated attackers can steal session cookies from other TranzAxis users and escalate privileges within a payment processing environment.
Affected Products
- Compass Plus Technologies TranzAxis 3.2.41.10.26
- Deployments exposing the Open Object in Tree endpoint to authenticated users
- Environments where TranzAxis administrator sessions can be triggered against attacker-controlled objects
Discovery Timeline
- 2025-12-04 - CVE-2025-66574 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66574
Vulnerability Analysis
TranzAxis is a payment processing platform used by financial institutions to manage card, account, and transaction data. The Open Object in Tree functionality accepts user-controlled input that is stored and later rendered within the administrative tree view. Because the application does not encode or filter HTML metacharacters, an authenticated attacker can persist a script payload that executes when another user opens the affected object.
The stored nature of the flaw makes it more impactful than reflected XSS. Payloads persist across sessions and fire automatically when victims navigate the tree. Attackers with low-privileged access can target higher-privileged operators, harvesting authentication material tied to core payment workflows.
Root Cause
The root cause is missing output encoding on data returned by the Open Object in Tree endpoint. Input submitted by an authenticated user is stored and later reflected into the DOM without HTML entity encoding or a Content Security Policy that restricts inline script execution. This mirrors classic [CWE-79] output-context handling failures.
Attack Vector
Exploitation requires authenticated access to TranzAxis and network reachability to the web interface. An attacker submits an object containing an embedded script payload through the vulnerable endpoint. When a privileged user opens the object in the tree, the browser executes the script under the victim's origin. The script can exfiltrate session cookies, perform actions on behalf of the victim, or pivot to administrative functions.
The vulnerability mechanism is documented in the Vulncheck advisory for TranzAxis XSS and in Exploit-DB entry 52086. No verified sanitized exploit code is reproduced here; refer to the linked advisories for technical detail.
Detection Methods for CVE-2025-66574
Indicators of Compromise
- Object names or tree entries in TranzAxis containing HTML tags such as <script>, <img onerror=, or <svg onload=
- Outbound HTTP requests from operator browsers to unfamiliar domains shortly after opening tree objects
- Session cookies for TranzAxis administrator accounts appearing in web server logs from unexpected source IPs
- Anomalous administrative actions performed by accounts that did not initiate the corresponding UI workflow
Detection Strategies
- Inspect stored TranzAxis object metadata for HTML or JavaScript syntax that should not appear in legitimate business data
- Monitor web application logs for requests to the Open Object in Tree endpoint containing encoded angle brackets or javascript: URIs
- Correlate authenticated user activity with subsequent privileged actions to identify session hijacking patterns
Monitoring Recommendations
- Enable verbose audit logging on the TranzAxis administrative interface and forward events to a centralized SIEM for correlation
- Alert on browser-based anomalies from operator workstations, including unexpected DOM script execution or cross-origin requests
- Track creation and modification of tree objects by low-privileged accounts, prioritizing review of any input containing markup characters
How to Mitigate CVE-2025-66574
Immediate Actions Required
- Restrict access to the TranzAxis administrative interface to trusted network segments and hardened jump hosts
- Audit existing tree objects for stored script payloads and remove any entries containing HTML or JavaScript content
- Rotate session cookies and force reauthentication for all operators after cleanup
- Contact Compass Plus Technologies through the vendor homepage for a fixed release or patched build
Patch Information
No vendor advisory URL is listed in the NVD entry at time of publication. Organizations running TranzAxis 3.2.41.10.26 should engage Compass Plus Technologies directly to obtain an official fix and confirm the remediated version. Refer to the Vulncheck advisory for tracking updates.
Workarounds
- Deploy a web application firewall rule that blocks requests to the Open Object in Tree endpoint containing <, >, or javascript: sequences in user-controllable parameters
- Enforce a strict Content Security Policy that disallows inline scripts on the TranzAxis administrative interface, if configurable at the reverse proxy
- Limit account privileges so that low-trust users cannot create or modify objects that administrators must open
- Apply short session timeouts and bind sessions to source IP where operationally feasible to reduce the value of stolen cookies
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
