Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP

Posted date 27/11/2025
Identificador
INCIBE-2026-136
Importance
3 - Medium
Affected Resources

Soteshop, version 8.3.4.

Description

INCIBE has coordinated the publication of one medium-severity vulnerability which affects SOTESHOP -an online sales software- version 8.3.4. This vulnerability was discovered by Gonzalo Aguilar García (6h4ack).

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2025-40701: CVSS v4.0: 5.1 | CVSS AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N | CWE-79 
Solution

The vulnerability has been fixed by the SOTE team in version 8.3.5.

Detail

CVE-2025-40701: reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.

CVE
Explotación
No
CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2025-40701 Media No SOTESHOP
References list
Etiquetas