CVE 5.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Lewe WebMeasure_CVE-2025-40697

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

Basic Information

ID CVE-2025-40697
Source INCIBE
Published Feb 19, 2026 at 08:44

Affected Product

Vendor Lewe
Product WebMeasure
Version all versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.