HTML Injection Vulnerability in HCL Software Products
CVE-2025-62320

4.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 March 2026

What is CVE-2025-62320?

This vulnerability occurs when HCL Software products fail to adequately sanitize user input before rendering it within web pages. This flaw allows malicious actors to inject arbitrary HTML code, which may lead to the execution of unauthorized actions or the retrieval of sensitive information. When the compromised page is loaded in a user's browser, the injected HTML can interact with external resources, potentially exposing users to additional risks and unintended consequences.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Sametime version 25.1.1 and below.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.