HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NHcltech Digital Experience
APPHcltech9.5Hcltech Digital Experience Compose
APPHcltech9.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-37538CRITICAL9.3PL ✓same product
Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary
CVE-2026-21837HIGH8.7same product
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management AP...
CVE-2020-14255HIGH7.5same product
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...
CVE-2026-21825MEDIUM6.1same product
HCL Digital Experience Compose jest podatny na reflected XSS w komponencie search center. Atakujący mógłby wyk...
CVE-2025-62326MEDIUM6.1same product
HCL Digital Experience jest podatny na stored XSS w interfejsie administratora, którego exploitacja wymaga pod...