Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
There is no solution reported at this time.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xcally
Xcally omnichannel |
|
| Vendors & Products |
Xcally
Xcally omnichannel |
Thu, 13 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user data, such as session cookies , or to perform actions on behalf of the user. | |
| Title | Cross-Site Scripting (XSS) in xCally Omnichannel | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-13T20:22:57.206Z
Reserved: 2025-04-16T08:38:16.029Z
Link: CVE-2025-40681
Updated: 2025-11-13T20:22:54.010Z
Status : Deferred
Published: 2025-11-13T13:15:45.537
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40681
No data.
OpenCVE Enrichment
Updated: 2025-11-14T09:27:56Z