No analysis available yet.
Vendor Solution
The vulnerability has been fixed by the PideTuCita team in version 6.0.52.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the endpoint 'cookies/indes.php/<XSS>'. This vulnerability can be exploited to steal confidential user data, such as session cookies or to perform actions on behalf of the user. | |
| Title | Reflected Cross-Site Scripting in PideTuCita | |
| First Time appeared |
Pidetucita
Pidetucita pidetucita |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:pidetucita:pidetucita:v6.0.52:*:*:*:*:*:*:* | |
| Vendors & Products |
Pidetucita
Pidetucita pidetucita |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-24T13:24:29.061Z
Reserved: 2025-04-16T09:08:37.855Z
Link: CVE-2025-40986
Updated: 2026-02-23T12:42:52.146Z
Status : Awaiting Analysis
Published: 2026-02-23T11:16:20.910
Modified: 2026-02-23T18:13:53.397
Link: CVE-2025-40986
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:27:53Z