Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter.
Cyber News related to CVE-2025-40978
CVE-2021-40978 - The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and ...
1 year ago
CVE-2025-40978 - Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ ...
56 years ago
CVE-2022-40978 - The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking ...
3 years ago
CVE-2024-40978 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago