CVE-2023-37502
—CVSS 3.1
8.8 high
EPSS
<1%p40
Published
()
Modified
Description
HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
- Vendors
- hcltech
- Products
- hcl compass
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.