Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such as session cookies or to perform actions on behalf of the victim.
History

Tue, 02 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such as session cookies or to perform actions on behalf of the victim.
Title Reflected Cross-Site Scripting (XSS) in Governalia by IDI Eikon
First Time appeared Idi Eikon
Idi Eikon governalia
Weaknesses CWE-79
CPEs cpe:2.3:a:idi_eikon:governalia:*:*:*:*:*:*:*:*
Vendors & Products Idi Eikon
Idi Eikon governalia
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-12-02T13:08:55.540Z

Updated: 2025-12-02T13:26:32.149Z

Reserved: 2025-04-16T08:38:18.261Z

Link: CVE-2025-40700

cve-icon Vulnrichment

Updated: 2025-12-02T13:26:22.676Z

cve-icon NVD

Status : Received

Published: 2025-12-02T13:15:53.537

Modified: 2025-12-02T13:15:53.537

Link: CVE-2025-40700

cve-icon Redhat

No data.