Reflected Cross-Site Scripting in PideTuCita

Posted date 27/11/2025
Identificador
INCIBE-2026-135
Importance
3 - Medium
Affected Resources

PideTuCita versions prior to v6.0.52.

Description

INCIBE has coordinated the publication of 1 vulnerability affecting PideTuCita. This vulnerability was discovered by Gonzalo Aguilar García (6h4ack).

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2025-40986: CVSS v4.0: 5.1 | CVSS AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N | CWE-79
Solution

The vulnerability has been fixed by the PideTuCita team in version 6.0.52.

Detail

CVE-2025-40986: reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the endpoint 'cookies/indes.php/<XSS>'. This vulnerability can be exploited to steal confidential user data, such as session cookies or to perform actions on behalf of the user.

CVE
Explotación
No
CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2025-40986 Media No PideTuCita
Etiquetas