HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-41420 HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2024-09-03T19:06:34.349Z

Reserved: 2023-07-06T16:29:45.712Z

Link: CVE-2023-37533

cve-icon Vulnrichment

Updated: 2024-08-02T17:16:30.417Z

cve-icon NVD

Status : Modified

Published: 2023-11-09T00:15:07.870

Modified: 2024-11-21T08:11:53.153

Link: CVE-2023-37533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.