Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_recuperarclave.php'.
PUBLISHED5.2CWE-79
Multiple vulnerabilities in GDTaller
Problem type
Affected products
GDTaller
GDTaller
< * - AFFECTED
References
JSON source
https://cveawg.mitre.org/api/cve/CVE-2025-41027Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-41027",
"assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516",
"assignerShortName": "INCIBE",
"dateUpdated": "2026-03-26T13:22:59.327Z",
"dateReserved": "2025-04-16T09:09:26.929Z",
"datePublished": "2026-03-26T12:42:05.425Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516",
"shortName": "INCIBE",
"dateUpdated": "2026-03-26T12:43:19.848Z"
},
"title": "Multiple vulnerabilities in GDTaller",
"descriptions": [
{
"lang": "en",
"value": "Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_recuperarclave.php'.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_recuperarclave.php'."
}
]
}
],
"affected": [
{
"vendor": "GDTaller",
"product": "GDTaller",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "*"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
"cweId": "CWE-79",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-gdtaller",
"tags": [
"patch"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"solutions": [
{
"lang": "en",
"value": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-gdtaller",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-gdtaller"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Gonzalo Aguilar García (6h4ack)",
"type": "finder"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-03-26T13:22:59.327Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}