VYPR
Medium severity6.1NVD Advisory· Published May 12, 2025· Updated Jun 17, 2026

CVE-2025-40627

CVE-2025-40627

Description

Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user, through "/eyes?

[XSS_PAYLOAD]".

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • AbanteCart/AbanteCartcpe-rescue3 versions
    1.4.0+ 2 more
    • (no CPE)range: 1.4.0
    • (no CPE)range: =1.4.0
    • cpe:2.3:a:abantecart:abantecart:1.4.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.