HIGH🇵🇱 Wersja polska

CVE-2023-37503

CVSS 8.1v3.1pub. 2023-10-19upd. 2024-11-21

HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
  • Hcltech Hcl Compass

    APP
    Hcltech
    2.1.02.0.0 – 2.0.32.2.0 – 2.2.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-37502CRITICAL9.0PL ✓same product

HCL Compass — niebezpieczne przesyłanie plików umożliwiające RCE

CVE-2022-42447CRITICAL9.6PL ✓same product

HCL Compass — błędna konfiguracja CORS umożliwia wykonanie złośliwych żądań

CVE-2023-37504HIGH7.1same product

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated...

CVE-2025-62319CRITICAL9.8PL ✓same vendor

Boolean-Based SQL Injection umożliwiający wstrzyknięcie dowolnego SQL

CVE-2023-37538CRITICAL9.3PL ✓same vendor

Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary