Impact
A reflected cross‑site scripting flaw (CWE‑79) exists in the search center of HCL Digital Experience Compose. The flaw allows an attacker to embed arbitrary JavaScript into the victim’s browser when a crafted search request is processed, enabling malicious code execution within the client context.
Affected Systems
The vulnerability affects the HCL Digital Experience Compose component from HCLSoftware. No specific version numbers are listed, so all installations may be susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score is currently unavailable, so the current exploit probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that a user visit a maliciously crafted URL in the search center; no authentication is required, and it is entirely client‑side, making it straightforward to test and deploy.
OpenCVE Enrichment