CVE-2025-62320: HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62320?
CVE-2025-62320 is classified as a critical vulnerability due to its potential for data exfiltration.
How do I fix CVE-2025-62320?
To fix CVE-2025-62320, ensure proper validation and sanitization of user inputs in the HCL Unica Platform web application.
What type of attack does CVE-2025-62320 allow?
CVE-2025-62320 allows for HTML injection, which can lead to data exfiltration to external servers.
Which software is affected by CVE-2025-62320?
CVE-2025-62320 affects the HCL Unica Platform specifically.
Can CVE-2025-62320 lead to unauthorized data access?
Yes, CVE-2025-62320 can facilitate unauthorized data access by exfiltrating sensitive information to external servers.