Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by Quiter team in the latest version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20458 | Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the id_concesion parameter in /<Client>FacturaE/VerFacturaPDF. |
Sat, 18 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quiter
Quiter quiter Gateway |
|
| CPEs | cpe:2.3:a:quiter:quiter_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Quiter
Quiter quiter Gateway |
|
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the id_concesion parameter in /<Client>FacturaE/VerFacturaPDF. | |
| Title | Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-10T10:14:17.091Z
Reserved: 2025-04-16T08:38:20.493Z
Link: CVE-2025-40719
Updated: 2025-07-08T15:41:12.498Z
Status : Analyzed
Published: 2025-07-08T12:15:23.090
Modified: 2025-10-18T01:33:16.980
Link: CVE-2025-40719
No data.
OpenCVE Enrichment
No data.
EUVD