CNNVD-202509-1544 Information

CNNVD ID

CNNVD-202509-1544

CVE-2025-40725

  • CNNVD Published: 2025-09-10

Description (Chinese)

Azon Dominator是Dev Webister个人开发者的一个网站开发工具。 Azon Dominator存在跨站脚本漏洞,该漏洞源于允许攻击者通过GET在/search中使用q参数发送恶意URL,从而在受害者的浏览器中执行JavaScript代码。

Description (English)

Azon Dominator is a website development tool for Dev Webister personal developers. Azon Dominator has a cross-site script loophole, which stems from allowing the attackers to send malicious URLs through the GET using q parameters in/search, thus implementing JavaScript code in the victim ’ s browser.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

个人开发者

Published

2025-09-10

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-azon-dominator

Patch

https://devwebister.gumroad.com/l/ThisIsWhyImBroke-theme

Share on: