NONE · 0

CVE-2025-40701

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parame...

Vulnerability Description

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-40701?

CVE-2025-40701 is a documented vulnerability. Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parame...

How severe is CVE-2025-40701?

CVSS scoring is not yet available for CVE-2025-40701. Check NVD for updates.

Is there a patch for CVE-2025-40701?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.