CVE-2025-40729

Publication date

2025-06-16 08:30:21

Family

INCIBE

State

PUBLISHED

Description

Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.