HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2023-11-08T23:17:18.712Z

Updated: 2024-09-03T19:06:34.349Z

Reserved: 2023-07-06T16:29:45.712Z

Link: CVE-2023-37533

cve-icon Vulnrichment

Updated: 2024-08-02T17:16:30.417Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-09T00:15:07.870

Modified: 2023-11-16T16:44:55.610

Link: CVE-2023-37533

cve-icon Redhat

No data.