CVE-2025-31994
⚪ Do wiadomości
Refleksyjne XSS w HCL Unica Campaign pozwala na wykonanie złośliwego skryptu w przeglądarce ofiary.
CVSS
4.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-13 04:15:55 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 12:10:00 UTC |