6.1
CVE-2025-62320
- EPSS 0.04%
- Veröffentlicht 17.03.2026 12:02:08
- Zuletzt bearbeitet 11.05.2026 14:18:40
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Unica Audience Central Version < 12.1.11
Hcltech ≫ Unica Audience Central Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Campaign Version < 12.1.11
Hcltech ≫ Unica Campaign Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Centralised Offer Management Version < 12.1.11
Hcltech ≫ Unica Centralised Offer Management Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Contact Central Version < 12.1.11
Hcltech ≫ Unica Contact Central Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Interact Version < 12.1.11
Hcltech ≫ Unica Interact Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Journey Version < 12.1.11
Hcltech ≫ Unica Journey Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Plan Version < 12.1.11
Hcltech ≫ Unica Plan Version >= 25.1.0 < 25.1.1.0.1
Hcltech ≫ Unica Segment Central Version < 12.1.11
Hcltech ≫ Unica Segment Central Version >= 25.1.0 < 25.1.1.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.104 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| psirt@hcl.com | 4.7 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.