PT-2024-13273 · Hcl · Hcl Connections Docs

Published

2024-06-08

·

Updated

2026-02-03

·

CVE-2023-45707

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL Connections Docs versions prior to 2.0.2
Description HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
Recommendations For versions prior to 2.0.2, update to a version later than 2.0.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-45707

Affected Products

Hcl Connections Docs