CVE Details
Basic Information
| Title | XSS in HotelRunner’s B2B |
|---|---|
| Type | cve |
| Published | 2025-07-22T13:53:59.638Z |
| Modified | 2025-07-22T14:08:59.350Z |
Product Information
| Vendor | HotelRunner |
|---|---|
| Product | B2B |
| Version | 0 |
CVSS Information
| Base Score | 4.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
AI Analysis
| AI Description | A Cross-Site Scripting (XSS) vulnerability in HotelRunner’s B2B platform allows attackers to execute malicious scripts in users’ browsers. This could lead to unauthorized actions, session hijacking, or data theft. The issue affects versions before 04.06.2025. |
|---|---|
| AI Severity | High |
| AI Vendor | HotelRunner |
| AI Product | HotelRunner B2B |
| AI Version | Before 04.06.2025 |
Affected Products
- HotelRunner B2B 0
Additional Information
| CWE List | CWE-79 |
|---|---|
| Source | TR-CERT |
Description
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in HotelRunner B2B allows Cross-Site Scripting (XSS). This issue affects B2B: before 04.06.2025.