CVE-2025-40729: Reflected Cross-Site Scripting (XSS) vulnerability in Customer Support System
Published Jun 16, 2025
·Updated
Reflected Cross-Site Scripting (XSS) in /customersupport/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.
Affected Software
2 affected components
Customer Support System Customer Support System
oretnom23 Customer Support System=1.0
Event History
Jun 16, 2025
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40729?
CVE-2025-40729 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2025-40729?
To mitigate CVE-2025-40729, sanitize and validate user input for the page parameter in /customer_support/index.php to prevent XSS attacks.
3
What software versions are affected by CVE-2025-40729?
Customer Support System v1.0 is the affected version related to CVE-2025-40729.
4
What type of vulnerability is CVE-2025-40729?
CVE-2025-40729 is categorized as a Reflected Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2025-40729 be exploited remotely?
Yes, CVE-2025-40729 can be exploited remotely by attackers through the page parameter.