CRITICAL🇵🇱 Wersja polska

CVE-2022-42447

CVSS 9.6v3.1pub. 2023-04-02upd. 2025-02-19

HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Hcltech Hcl Compass

    APP
    Hcltech
    2.0.0 – 2.0.32.1.0 – 2.2.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-37502CRITICAL9.0PL ✓same product

HCL Compass — niebezpieczne przesyłanie plików umożliwiające RCE

CVE-2023-37503HIGH8.1same product

HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and g...

CVE-2023-37504HIGH7.1same product

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated...

CVE-2025-62319CRITICAL9.8PL ✓same vendor

Boolean-Based SQL Injection umożliwiający wstrzyknięcie dowolnego SQL

CVE-2023-37538CRITICAL9.3PL ✓same vendor

Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary