No analysis available yet.
Vendor Solution
The vulnerability has been fixed by the SOTE team in version 8.3.5.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf. | |
| Title | Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP | |
| First Time appeared |
Sote
Sote soteshop |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:sote:soteshop:8.3.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Sote
Sote soteshop |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-24T13:25:45.940Z
Reserved: 2025-04-16T08:38:18.261Z
Link: CVE-2025-40701
Updated: 2026-02-23T12:43:51.084Z
Status : Awaiting Analysis
Published: 2026-02-23T11:16:20.680
Modified: 2026-02-23T18:13:53.397
Link: CVE-2025-40701
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:27:54Z