Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_login.php'.
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilities has been fixed by the GDTaller team in the current version.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL en 'site' parameter in 'app_login.php'. | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_login.php'. |
Thu, 26 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL en 'site' parameter in 'app_login.php'. | |
| Title | Multiple vulnerabilities in GDTaller | |
| First Time appeared |
Gdtaller
Gdtaller gdtaller |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:gdtaller:gdtaller:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gdtaller
Gdtaller gdtaller |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-26T13:23:17.835Z
Reserved: 2025-04-16T09:09:26.929Z
Link: CVE-2025-41026
No data.
Status : Received
Published: 2026-03-26T13:16:24.903
Modified: 2026-03-26T13:16:24.903
Link: CVE-2025-41026
No data.
OpenCVE Enrichment
No data.
Weaknesses