ZeroHour

CVE-2022-38660

CVSS 3.1
8.8 high
EPSS
<1%p22
Published
()
Modified
Description

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.

Vendors
hcltech
Products
domino
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.