VYPR
Unrated severityNVD Advisory· Published Apr 29, 2024· Updated Aug 1, 2024

Cross-site Scripting (XSS) vulnerability in HubBank

CVE-2024-4310

Description

Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.