Cross-Site Scripting Vulnerability in HCL DevOps Plan
CVE-2023-37508

2.3LOW

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2023-37508?

HCL DevOps Plan has a vulnerability that may allow attackers to exploit Cross-Site Scripting (XSS) weaknesses, particularly within specific browser environments. This flaw could enable malicious actors to inject harmful scripts into web pages, potentially compromising user data and session integrity. It is essential for users to assess their security posture and implement best practices to mitigate potential threats.

Affected Version(s)

DevOps Plan <3.0.05

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.