Impact
The HubCore platform version 14.1.1 contains a cross‑site scripting flaw in the /loginController/doLogin endpoint. An unchecked language POST parameter permits a remote, unauthenticated attacker to embed arbitrary JavaScript into the application’s response. Executed code runs in the victim’s browser context, enabling session theft, UI defacement, or phishing, all without needing prior authentication.
Affected Systems
Deployments using HubCore 14.1.1 are affected. No additional vendor or product details are specified in the CVE record.
Risk and Exploitability
The vulnerability is remote and does not require authentication, so attackers can trigger it from any location by posting a malicious request to /loginController/doLogin. Because the POST parameter is not validated or sanitized, exploitation is straightforward. The CVSS score is 6.1, indicating medium severity. The EPSS score is <1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment