A Persistent Cross-site Scripting (XSS) vulnerability affects HCL Unica Campaign
CVE-2023-37501

8.1HIGH

Key Information:

Vendor
CVE Published:
3 August 2023

What is CVE-2023-37501?

A Persistent Cross-Site Scripting (XSS) vulnerability exists in Unica Campaign, allowing attackers to inject malicious scripts into certain fields. This can lead to session hijacking, enabling the attacker to take control of a user's session and perform unauthorized actions on their behalf. Proper input validation and sanitization are essential to mitigate this vulnerability. For more details, refer to the HCL Technologies knowledge base.

Affected Version(s)

HCL Unica Campaign <12.1.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.