First published: Wed Oct 11 2023(Updated: )
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
Credit: psirt@hcl.com psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Digital Experience | =8.5 | |
Hcltech Digital Experience | =9.0 | |
Hcltech Digital Experience | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-37538.
The severity of CVE-2023-37538 is critical.
Versions 8.5, 9.0, and 9.5 of HCL Digital Experience are affected by CVE-2023-37538.
The CWE category associated with CVE-2023-37538 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2023-37538, it is recommended to apply the latest security patch provided by HCLTech or follow the instructions in the HCLTech support article: [https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108006](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108006)