Cross-Site Scripting Vulnerability in HotelRunner B2B Software
CVE-2025-4294
4.8MEDIUM
What is CVE-2025-4294?
A Cross-Site Scripting (XSS) vulnerability exists in the HotelRunner B2B platform that allows attackers to inject malicious scripts into web pages. This vulnerability can be exploited to execute unauthorized scripts in users' browsers, potentially leading to data theft or session hijacking. Affected versions of HotelRunner B2B must be updated before June 4, 2025, to mitigate the risk associated with this security flaw.
Affected Version(s)
B2B 0 < 04.06.2025