CVE-2025-40701

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Feb 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 11:16

Updated : 2026-02-23 18:13


NVD link : CVE-2025-40701

Mitre link : CVE-2025-40701

CVE.ORG link : CVE-2025-40701


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')