First published: Thu Dec 21 2023(Updated: )
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Launch | >=7.1.0.0<=7.1.2.14 | |
HCL Launch | >=7.2.0.0<=7.2.3.7 | |
HCL Launch | >=7.3.0.0<=7.3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-45700 is categorized as a moderate vulnerability due to the potential for sensitive information disclosure.
To fix CVE-2023-45700, upgrade to HCL Launch versions 7.1.2.14 or later, 7.2.3.7 or later, or 7.3.2.2 or later.
CVE-2023-45700 allows attackers to embed arbitrary HTML tags in the Web UI, potentially leading to sensitive information disclosure.
HCL Launch versions from 7.1.0.0 to 7.1.2.14, from 7.2.0.0 to 7.2.3.7, and from 7.3.0.0 to 7.3.2.2 are affected by CVE-2023-45700.
There is no documented temporary workaround for CVE-2023-45700, and the recommended action is to update to a patched version.