Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf. | |
| Title | Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP | |
| First Time appeared |
Sote
Sote soteshop |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:sote:soteshop:8.3.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Sote
Sote soteshop |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-23T12:44:00.221Z
Reserved: 2025-04-16T08:38:18.261Z
Link: CVE-2025-40701
No data.
Status : Received
Published: 2026-02-23T11:16:20.680
Modified: 2026-02-23T11:16:20.680
Link: CVE-2025-40701
No data.
OpenCVE Enrichment
No data.