{"id":"CVE-2025-40725","title":"Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator","summary":"Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the “q” parameter in /search via GET. Th…","severity":"none","cwe":["CWE-79"],"published":"2025-09-10","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40725","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-azon-dominator","label":"cve-coordination@incibe.es"}],"tags":["nvd"],"epss":0.00328,"epssPercentile":0.23258,"ingestedAt":"2026-09-26T00:22:39.910Z","slug":"CVE-2025-40725","body":"## Overview\n\nReflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the “q” parameter in /search via GET. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}