Description
Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43955 | Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover. |
References
History
Wed, 23 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ofofonobsdev
Ofofonobsdev hubbank |
|
| CPEs | cpe:2.3:a:ofofonobsdev:hubbank:1.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ofofonobsdev
Ofofonobsdev hubbank |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:33:53.174Z
Reserved: 2024-04-29T10:10:08.692Z
Link: CVE-2024-4310
Updated: 2024-08-01T20:33:53.174Z
Status : Analyzed
Published: 2024-04-29T13:15:32.050
Modified: 2025-04-23T16:35:48.543
Link: CVE-2024-4310
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD