PT-2026-29448 · Bufanyun · Hotgo

·

CVE-2026-5253

·

Published

2026-04-01

·

Updated

2026-04-01

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions bufanyun HotGo versions 1.0 through 2.0
Description A weakness exists in bufanyun HotGo versions 1.0 and 2.0. The issue affects an unknown functionality within the /web/src/layout/components/Header/MessageList.vue file of the editNotice endpoint component. Manipulating this functionality can lead to cross site scripting (XSS). The attack can be launched remotely, and an exploit is publicly available. The vendor was contacted regarding this disclosure but did not respond.
Recommendations For versions 1.0 and 2.0, address the vulnerability in the /web/src/layout/components/Header/MessageList.vue file of the editNotice endpoint component to prevent cross site scripting.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5253

Affected Products

Hotgo