HCL Digital Experience is susceptible to cross-site scripting (XSS)
CVE-2022-38653

2LOW

Key Information:

Vendor
CVE Published:
19 December 2022

Summary

In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

Affected Version(s)

HCL Digital Experience 8.5, 9.0, 9.5

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.