First published: Thu Sep 22 2022(Updated: )
User input included in error response, which could be used in a phishing attack.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Hcl Digital Experience | =8.5 | |
Hcltech Hcl Digital Experience | =9.0 | |
Hcltech Hcl Digital Experience | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-27774.
The severity of CVE-2021-27774 is medium with a severity value of 5.4.
CVE-2021-27774 is a vulnerability where user input included in error response can be used in a phishing attack.
Versions 8.5, 9.0, and 9.5 of Hcltech Hcl Digital Experience are affected by CVE-2021-27774.
To mitigate CVE-2021-27774, it is recommended to sanitize user input and avoid including it in error responses.