Cross-Site Scripting Vulnerability in HCL Traveler by HCL Technologies
CVE-2019-4409

5.4MEDIUM

Key Information:

Vendor
CVE Published:
18 October 2019

Summary

HCL Traveler versions 9.x and earlier contain a vulnerability that may allow cross-site scripting (XSS) attacks. Specifically, when users submit an invalid file name on the Problem Report page of the Traveler servlet, the application returns an error message displaying the inputted file name. If this output is not properly sanitized, it can lead to the execution of malicious scripts in the context of other users' browsers, potentially compromising sensitive information and application security. Organizations using affected versions should prioritize applying fixes to mitigate these risks.

Affected Version(s)

HCL Traveler 9.x and earlier versions

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.