CVE-2022-38653

In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltech:digital_experience:8.5:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:digital_experience:9.0:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:digital_experience:9.5:*:*:*:*:*:*:*

History

21 Nov 2024, 07:16

Type Values Removed Values Added
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102141 - Vendor Advisory () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102141 - Vendor Advisory
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 2.0

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded. In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

Information

Published : 2022-12-19 11:15

Updated : 2024-11-21 07:16


NVD link : CVE-2022-38653

Mitre link : CVE-2022-38653

CVE.ORG link : CVE-2022-38653


JSON object : View

Products Affected

hcltech

  • digital_experience
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')