HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NHcltech Digital Experience
APPHcltech8.59.09.5
Related vulnerabilities
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management AP...
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...
HCL Digital Experience i HCL Digital Experience Compose mogą być podatne na Host header injection. Atakujący m...
HCL Digital Experience Compose jest podatny na reflected XSS w komponencie search center. Atakujący mógłby wyk...
HCL Digital Experience jest podatny na stored XSS w interfejsie administratora, którego exploitacja wymaga pod...