First published: Thu Mar 30 2023(Updated: )
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Launch | >=6.2.0.0<=6.2.7.18 | |
HCL Launch | >=7.0.5.0<=7.0.5.13 | |
HCL Launch | >=7.1.0.0<=7.1.2.9 | |
HCL Launch | >=7.2.0.0<=7.2.3.2 | |
HCL Launch | =7.3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42452 is a vulnerability in HCL Launch where HTML code is stored and included without being sanitized, leading to potential attacks like XSS and Open Redirections.
CVE-2022-42452 has a severity rating of 5.4, which is considered medium.
HCL Launch versions 6.2.0.0 to 6.2.7.18, 7.0.5.0 to 7.0.5.13, 7.1.0.0 to 7.1.2.9, 7.2.0.0 to 7.2.3.2, and 7.3.0.0 are affected by CVE-2022-42452.
To fix CVE-2022-42452, it is recommended to update HCL Launch to a version that includes a fix for this vulnerability.
More information about CVE-2022-42452 can be found in the following article: [link](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102081).