Cross-Site Scripting Vulnerability in HCL Traveler by HCL Technologies
CVE-2019-4409
What is CVE-2019-4409?
HCL Traveler versions 9.x and earlier contain a vulnerability that may allow cross-site scripting (XSS) attacks. Specifically, when users submit an invalid file name on the Problem Report page of the Traveler servlet, the application returns an error message displaying the inputted file name. If this output is not properly sanitized, it can lead to the execution of malicious scripts in the context of other users' browsers, potentially compromising sensitive information and application security. Organizations using affected versions should prioritize applying fixes to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HCL Traveler 9.x and earlier versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved