CVE-2026-75170
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 04, 2026
Vendor
unknown
Description
Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter.