CVE-2025-41027 describes a Reflected Cross-Site Scripting (XSS) vulnerability in GDTaller, specifically within the 'site' parameter of 'app_recuperarclave.php', which allows an attacker to execute arbitrary JavaScript in a victim's browser. Rated Medium (CVSS 6.1), this vulnerability has a network attack vector and low complexity, requiring user interaction to trick a victim into clicking a malicious URL, potentially leading to limited confidentiality and integrity impacts. There is currently no evidence of active exploitation, nor are public exploit modules available in Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gdtaller:gdtaller:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.