Cross-Site Scripting Vulnerability in HCL Digital Experience
CVE-2025-31988
4.9MEDIUM
What is CVE-2025-31988?
HCL Digital Experience contains a cross-site scripting vulnerability within its administrative UI, which is accessible with restricted access. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising sensitive information. It is crucial for users of HCL Digital Experience to apply the recommended mitigations and updates to secure their applications against potential exploits.
Affected Version(s)
Digital Experience 8.5, 9.0, 9.5