HTML Injection Vulnerability in HCL Software Products
CVE-2025-62320
4.7MEDIUM
What is CVE-2025-62320?
This vulnerability occurs when HCL Software products fail to adequately sanitize user input before rendering it within web pages. This flaw allows malicious actors to inject arbitrary HTML code, which may lead to the execution of unauthorized actions or the retrieval of sensitive information. When the compromised page is loaded in a user's browser, the injected HTML can interact with external resources, potentially exposing users to additional risks and unintended consequences.
Affected Version(s)
Sametime version 25.1.1 and below.