A Persistent Cross-site Scripting (XSS) vulnerability affects HCL Unica Platform
CVE-2023-37500
8.1HIGH
Summary
A persistent Cross-site Scripting (XSS) vulnerability exists in the HCL Unica Platform, enabling attackers to inject malicious scripts on certain pages. This issue allows unauthorized users to hijack valid user sessions, potentially leading to further exploitation or data theft. Organizations using affected versions of Unica must implement mitigation strategies to secure their applications.
Affected Version(s)
HCL Unica Platform <12.1.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved