ZeroHour

CVE-2025-31966

CVSS 3.1
2.7 low
EPSS
<1%p9
Published
()
Modified
Description

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

Vendors
hcltech
Products
sametime
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.