Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the “q” parameter in /search via GET. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Metrics
Affected Vendors & Products
Fixes
Solution
The vulnerability has been fixed by the Azon Dominator team in the latest available version.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Sep 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the “q” parameter in /search via GET. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
Title | Reflected Cross-Site Scripting (XSS) in Azon Dominator | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-10T14:34:58.155Z
Reserved: 2025-04-16T08:38:23.940Z
Link: CVE-2025-40725

No data.

Status : Received
Published: 2025-09-10T12:15:33.043
Modified: 2025-09-10T12:15:33.043
Link: CVE-2025-40725

No data.

No data.