Junglewise Threat Intelligence

CVE-2025-4294: HotelRunner B2B Cross-Site Scripting

CVE-2025-4294 · Severity: medium · CVSS 4.8 · Published 2025-07-22

Technologies: HotelRunner B2B. Vendors: HotelRunner.

Executive brief

A security vulnerability exists in HotelRunner B2B, a platform used for business-to-business travel and hospitality management. An attacker could inject malicious scripts into the platform, which would then execute in the browser of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in HotelRunner B2B versions prior to 04.06.2025. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with high privileges (PR:H) can exploit this over the network by injecting malicious scripts that execute when a victim interacts with the affected page (UI:R). This allows for limited impact on confidentiality and integrity within a different security scope (S:C). The issue was addressed in the update released on June 4, 2025.

Affected products

  • HotelRunner B2B before 04.06.2025

Timeline

  • 2025-07-22: disclosed
  • 2025-07-22: advisory
  • 2025-06-04: patched

References

Related threats