PT-2025-23084 · Unknown · Real Easy Store

Edgar Carrillo

·

Published

2025-05-28

·

Updated

2025-05-28

·

CVE-2025-40651

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Real Easy Store (affected versions not specified)
Description A Reflected Cross-Site Scripting (XSS) issue allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL using the keyword parameter in "/index.php?a=search". This can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-40651

Affected Products

Real Easy Store