First published: Tue Jun 25 2024(Updated: )
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30112 has a medium severity level, indicating potential risks to user data due to cross-site scripting vulnerabilities.
To fix CVE-2024-30112, it is recommended to apply the latest patches provided by HCL for the Connections software.
CVE-2024-30112 is classified as a cross-site scripting (XSS) vulnerability.
Users affected by CVE-2024-30112 may have their session cookies stolen, allowing attackers to impersonate them.
CVE-2024-30112 affects users of HCL Connections who access the application in an unsafe manner.