CVE-2023-45700: HCL Launch is susceptible to an HTML injection vulnerability
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45700?
The severity of CVE-2023-45700 is categorized as a moderate vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2023-45700?
To fix CVE-2023-45700, upgrade to HCL Launch versions 7.1.2.14 or later, 7.2.3.7 or later, or 7.3.2.2 or later.
What does CVE-2023-45700 vulnerability allow attackers to do?
CVE-2023-45700 allows attackers to embed arbitrary HTML tags in the Web UI, potentially leading to sensitive information disclosure.
Which versions of HCL Launch are affected by CVE-2023-45700?
HCL Launch versions from 7.1.0.0 to 7.1.2.14, from 7.2.0.0 to 7.2.3.7, and from 7.3.0.0 to 7.3.2.2 are affected by CVE-2023-45700.
Is there a temporary workaround for CVE-2023-45700?
There is no documented temporary workaround for CVE-2023-45700, and the recommended action is to update to a patched version.