Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 10, 2025
Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway
CVE-2025-40720
Description
Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the campo parameter in /FacturaE/VerFacturaPDF.
Affected products
2- Range: <4.7.0
- Quiter/Quiter Gateway (Java WAR on Apache Tomcat)v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.