---
id: CVE-2025-15170
title: >-
  A security vulnerability has been detected in Advaya Softech GEMS ERP Portal
  up to 2.1
summary: >-
  A security vulnerability has been detected in Advaya Softech GEMS ERP Portal
  up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of
  the component Error Message Handler. The manipulation of the argument Message
  lead…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
  - CWE-79
vendor: advayasoftech
product: gems_erp_portal
affected:
  - gems_erp_portal <= 2.1
published: '2025-12-29'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15170'
references:
  - url: 'https://syansec.in/video_poc/cve_2025.mp4'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338550'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338550'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.717590'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00367
epssPercentile: 0.28122
ingestedAt: '2026-09-30T23:29:32.513Z'
---

## Overview

A security vulnerability has been detected in Advaya Softech GEMS ERP Portal up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of the component Error Message Handler. The manipulation of the argument Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `gems_erp_portal <= 2.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
