CVE-2022-42452

HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:7.3.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 4.6
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102081 - Vendor Advisory () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102081 - Vendor Advisory

07 Nov 2023, 03:53

Type Values Removed Values Added
Summary HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.

Information

Published : 2023-04-02 21:15

Updated : 2024-11-21 07:24


NVD link : CVE-2022-42452

Mitre link : CVE-2022-42452

CVE.ORG link : CVE-2022-42452


JSON object : View

Products Affected

hcltechsw

  • hcl_launch
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')