Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lewe
Lewe webmeasure |
|
| Vendors & Products |
Lewe
Lewe webmeasure |
Thu, 19 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to execute arbitrary code through the 'page' parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Reflected Cross-Site Scripting (XSS) in Lewe WebMeasure | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-02-19T08:44:16.386Z
Updated: 2026-02-20T16:08:24.444Z
Reserved: 2025-04-16T08:38:18.261Z
Link: CVE-2025-40697
Updated: 2026-02-20T16:07:12.516Z
Status : Awaiting Analysis
Published: 2026-02-19T09:16:11.060
Modified: 2026-02-19T15:52:39.260
Link: CVE-2025-40697
No data.