XSS in HotelRunner’s B2B

CVE Details

Basic Information

Title XSS in HotelRunner’s B2B
Type cve
Published 2025-07-22T13:53:59.638Z
Modified 2025-07-22T14:08:59.350Z

Product Information

Vendor HotelRunner
Product B2B
Version 0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Analysis

AI Description A Cross-Site Scripting (XSS) vulnerability in HotelRunner’s B2B platform allows attackers to execute malicious scripts in users’ browsers. This could lead to unauthorized actions, session hijacking, or data theft. The issue affects versions before 04.06.2025.
AI Severity High
AI Vendor HotelRunner
AI Product HotelRunner B2B
AI Version Before 04.06.2025

Affected Products

  • HotelRunner B2B 0

Additional Information

CWE List CWE-79
Source TR-CERT

Description

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in HotelRunner B2B allows Cross-Site Scripting (XSS). This issue affects B2B: before 04.06.2025.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.