PT-2025-43999 · Unknown · Rubikon Banking Solution

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-60983

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rubikon Banking Solution version 4.0.3
Description A reflected cross-site scripting issue exists in the "Search For Customers Information" endpoints of Rubikon Banking Solution. This allows for the injection of malicious scripts through reflected input. The Search For Customers Information endpoint is vulnerable. The vulnerable parameter is not specified.
Recommendations Apply input validation and output encoding to the Search For Customers Information endpoint to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60983

Affected Products

Rubikon Banking Solution