{"id":"CVE-2025-40681","title":"Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1","summary":"Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' param…","severity":"none","cwe":["CWE-79"],"published":"2025-11-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40681","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-xcally-omnichannel","label":"cve-coordination@incibe.es"}],"tags":["nvd"],"epss":0.00306,"epssPercentile":0.21458,"ingestedAt":"2026-10-07T21:54:15.030Z","slug":"CVE-2025-40681","body":"## Overview\n\nCross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user data, such as session cookies , or to perform actions on behalf of the user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}