CVE-2023-30454: Ebankit
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in ebankIT before 7. Document Object Model based XSS exists within the /Security/Transactions/Transactions.aspx endpoint. Users can supply their own JavaScript within the ctl100$ctl00MainContent$TransactionMainContent$accControl$hdnAccountsArray POST parameter that will be passed to an eval() function and executed upon pressing the continue button.
Affected products
- Ebankit Ebankit: before 7.0 (fixed in 7.0)
Published 2023-04-28. Last modified 2026-06-17.