CVE-2024-4310: Ofofonobsdev Hubbank
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover.
Affected products
- Ofofonobsdev Hubbank: version 1.0.2 only
Published 2024-04-29. Last modified 2026-06-17.