Project Subscriptions
No advisories yet.
Solution
The vulnerability has been fixed by the IDI Eikon team in version 1274.
Workaround
No workaround given by the vendor.
Fri, 30 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Idieikon
Idieikon governalia |
|
| CPEs | cpe:2.3:a:idieikon:governalia:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Idieikon
Idieikon governalia |
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such as session cookies or to perform actions on behalf of the victim. | |
| Title | Reflected Cross-Site Scripting (XSS) in Governalia by IDI Eikon | |
| First Time appeared |
Idi Eikon
Idi Eikon governalia |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:idi_eikon:governalia:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Idi Eikon
Idi Eikon governalia |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T13:26:32.149Z
Reserved: 2025-04-16T08:38:18.261Z
Link: CVE-2025-40700
Updated: 2025-12-02T13:26:22.676Z
Status : Analyzed
Published: 2025-12-02T13:15:53.537
Modified: 2026-01-30T19:13:04.337
Link: CVE-2025-40700
No data.
OpenCVE Enrichment
No data.