Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by Quiter team in the latest version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20457 | Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the campo parameter in /<Client>FacturaE/VerFacturaPDF. |
Sat, 18 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quiter
Quiter quiter Gateway |
|
| CPEs | cpe:2.3:a:quiter:quiter_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Quiter
Quiter quiter Gateway |
|
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the campo parameter in /<Client>FacturaE/VerFacturaPDF. | |
| Title | Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-10T10:14:29.087Z
Reserved: 2025-04-16T08:38:20.493Z
Link: CVE-2025-40720
Updated: 2025-07-08T15:36:27.524Z
Status : Analyzed
Published: 2025-07-08T12:15:23.243
Modified: 2025-10-18T01:32:26.137
Link: CVE-2025-40720
No data.
OpenCVE Enrichment
No data.
EUVD