CVE-2024-4310: Ofofonobsdev Hubbank

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover.

Affected products

Published 2024-04-29. Last modified 2026-06-17.