Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the endpoint 'cookies/indes.php/<XSS>'. This vulnerability can be exploited to steal confidential user data, such as session cookies or to perform actions on behalf of the user.
Advisories
No advisories yet.
Fixes
Solution
The vulnerability has been fixed by the PideTuCita team in version 6.0.52.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Feb 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the endpoint 'cookies/indes.php/<XSS>'. This vulnerability can be exploited to steal confidential user data, such as session cookies or to perform actions on behalf of the user. | |
| Title | Reflected Cross-Site Scripting in PideTuCita | |
| First Time appeared |
Pidetucita
Pidetucita pidetucita |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:pidetucita:pidetucita:v6.0.52:*:*:*:*:*:*:* | |
| Vendors & Products |
Pidetucita
Pidetucita pidetucita |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-23T10:31:25.455Z
Reserved: 2025-04-16T09:08:37.855Z
Link: CVE-2025-40986
No data.
Status : Received
Published: 2026-02-23T11:16:20.910
Modified: 2026-02-23T11:16:20.910
Link: CVE-2025-40986
No data.
OpenCVE Enrichment
No data.
Weaknesses