CVE-2021-27778: HCL Traveler is susceptible to a cross-site scripting vulnerability which could allow an attacker to execute a malicious script to access sensitive information.
Published May 31, 2022
·Updated
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
Affected Software
1 affected component
hcltech Traveler<=12.0.1.0
Event History
May 31, 2022
CVE Published
via MITRE·11:50 PM
Data Sourced
via MITRE·11:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27778.
2
What is the severity of CVE-2021-27778?
The severity of CVE-2021-27778 is medium.
3
What is the affected software?
The affected software is HCL Traveler version 12.0.1.0.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix CVE-2021-27778?
To fix CVE-2021-27778, update HCL Traveler to a version that includes the proper validation of the Name parameter.