PT-2023-21483 · Hcl · Hcl Connections

Published

2023-12-06

·

Updated

2023-12-12

·

CVE-2023-28017

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL Connections (affected versions not specified)
Description The issue allows an attacker to execute arbitrary script code in the browser of an unsuspecting user after visiting a vulnerable URL, leading to the execution of malicious script code. This may enable the attacker to steal cookie-based authentication credentials and compromise a user's account, then launch other attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28017

Affected Products

Hcl Connections