Reflected XSS Vulnerability in Real Easy Store by Real Easy
CVE-2025-40651
5.1MEDIUM
What is CVE-2025-40651?
A reflected cross-site scripting (XSS) vulnerability exists in Real Easy Store that allows attackers to inject and execute malicious JavaScript code. By crafting a malicious URL containing the keyword parameter in the /index.php?a=search endpoint, an attacker can trick victims into clicking the link. This could lead to the unauthorized access of sensitive information such as session cookies or enable unauthorized actions performed in the context of the user, thereby compromising user security.
Affected Version(s)
Real Easy Store all versions
