VYPR
Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 10, 2025

Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway

CVE-2025-40721

Description

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the id_factura parameter in /FacturaE/listado_facturas_ficha.jsp.

Affected products

2
  • Range: <4.7.0
  • Quiter/Quiter Gateway (Java WAR on Apache Tomcat)v5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.