Description
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
Published: 2023-11-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-41420 HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
History

No history.

Subscriptions

Hcltech Connections
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2024-09-03T19:06:34.349Z

Reserved: 2023-07-06T16:29:45.712Z

Link: CVE-2023-37533

cve-icon Vulnrichment

Updated: 2024-08-02T17:16:30.417Z

cve-icon NVD

Status : Modified

Published: 2023-11-09T00:15:07.870

Modified: 2024-11-21T08:11:53.153

Link: CVE-2023-37533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses