CVE-2019-4091: XSS
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4091?
CVE-2019-4091 is categorized as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2019-4091?
To fix CVE-2019-4091, you should upgrade to the latest version of HCL Marketing Platform that addresses this vulnerability.
What versions of HCL Marketing Platform are affected by CVE-2019-4091?
CVE-2019-4091 affects HCL Marketing Platform versions prior to 10.1.0.4, 11.1.0.3, and the exact version 9.1.2.4.
What risks are associated with CVE-2019-4091?
The risks associated with CVE-2019-4091 include unauthorized execution of malicious scripts that could compromise user data or system integrity.
Is there a workaround for CVE-2019-4091?
While upgrading is the recommended solution, a temporary workaround involves restricting access to the user addition and search functionalities until the upgrade can be performed.