Cross-Site Scripting Vulnerability in HCL Digital Experience
CVE-2025-31988

4.9MEDIUM

Key Information:

Vendor
CVE Published:
19 August 2025

What is CVE-2025-31988?

HCL Digital Experience contains a cross-site scripting vulnerability within its administrative UI, which is accessible with restricted access. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising sensitive information. It is crucial for users of HCL Digital Experience to apply the recommended mitigations and updates to secure their applications against potential exploits.

Affected Version(s)

Digital Experience 8.5, 9.0, 9.5

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31988 : Cross-Site Scripting Vulnerability in HCL Digital Experience