CRITICAL🇵🇱 Wersja polska

CVE-2023-37538

CVSS 9.3v3.1pub. 2023-10-11upd. 2024-11-21

HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Hcltech Digital Experience

    APP
    Hcltech
    8.59.09.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-21837HIGH8.7same product

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management AP...

CVE-2020-14255HIGH7.5same product

HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...

CVE-2026-21826MEDIUM6.1same product

HCL Digital Experience i HCL Digital Experience Compose mogą być podatne na Host header injection. Atakujący m...

CVE-2026-21825MEDIUM6.1same product

HCL Digital Experience Compose jest podatny na reflected XSS w komponencie search center. Atakujący mógłby wyk...

CVE-2025-62326MEDIUM6.1same product

HCL Digital Experience jest podatny na stored XSS w interfejsie administratora, którego exploitacja wymaga pod...