HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NHcltech Digital Experience
APPHcltech9.5Hcltech Digital Experience Compose
APPHcltech9.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2023-37538CRITICAL9.3PL ✓same product
Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary
CVE-2026-21837HIGH8.7same product
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management AP...
CVE-2020-14255HIGH7.5same product
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...
CVE-2026-21826MEDIUM6.1same product
HCL Digital Experience i HCL Digital Experience Compose mogą być podatne na Host header injection. Atakujący m...
CVE-2025-62326MEDIUM6.1same product
HCL Digital Experience jest podatny na stored XSS w interfejsie administratora, którego exploitacja wymaga pod...