HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HHcltech Hcl Compass
APPHcltech2.1.02.0.0 – 2.0.32.2.0 – 2.2.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-42447CRITICAL9.6PL ✓same product
HCL Compass — błędna konfiguracja CORS umożliwia wykonanie złośliwych żądań
CVE-2023-37503HIGH8.1same product
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and g...
CVE-2023-37504HIGH7.1same product
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated...
CVE-2025-62319CRITICAL9.8PL ✓same vendor
Boolean-Based SQL Injection umożliwiający wstrzyknięcie dowolnego SQL
CVE-2023-37538CRITICAL9.3PL ✓same vendor
Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary