HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHcltech Digital Experience
APPHcltech9.5Hcltech Digital Experience Compose
APPHcltech9.5
Related vulnerabilities
Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...
HCL Digital Experience i HCL Digital Experience Compose mogą być podatne na Host header injection. Atakujący m...
HCL Digital Experience Compose jest podatny na reflected XSS w komponencie search center. Atakujący mógłby wyk...
HCL Digital Experience jest podatny na stored XSS w interfejsie administratora, którego exploitacja wymaga pod...