First published: Wed Jul 26 2023(Updated: )
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Verse | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HCL Verse vulnerability is CVE-2023-28013.
CVE-2023-28013 has a severity rating of 6.1, which is classified as medium.
The Reflected Cross Site Scripting (XSS) vulnerability in HCL Verse allows a remote attacker to execute malicious scripts in a victim's browser by tricking them into entering specially crafted markup.
An attacker can exploit CVE-2023-28013 by tricking a user into entering crafted markup, which allows the attacker to execute scripts in the victim's browser and potentially perform unauthorized operations or steal sensitive information.
Yes, please refer to the official HCL Tech support website for information on available patches or updates to fix the vulnerability.