Aller au contenu

Fiche vulnérabilité

CVE-2025-40700 : faille moyenne idieikon governalia (CVSS 6.1)

Description

Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such as session cookies or to perform actions on behalf of the victim.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
2 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • idieikon governalia

Références

Rechercher une autre vulnérabilité dans la base CVE