ZeroHour

CVE-2023-37502

CVSS 3.1
8.8 high
EPSS
<1%p40
Published
()
Modified
Description

HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.

Vendors
hcltech
Products
hcl compass
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.