Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Low
CVE-2019-11358
Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6
Attacker Value
Unknown
CVE-2020-11022
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
4
Attacker Value
Unknown
CVE-2023-37538
Disclosure Date: October 11, 2023 (last updated October 19, 2023)
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
0
Attacker Value
Unknown
CVE-2022-38662
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
0
Attacker Value
Unknown
CVE-2022-38653
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
0
Attacker Value
Unknown
CVE-2021-27774
Disclosure Date: September 13, 2022 (last updated October 08, 2023)
User input included in error response, which could be used in a phishing attack.
0
Attacker Value
Unknown
CVE-2021-29425
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
0
Attacker Value
Unknown
CVE-2020-4081
Disclosure Date: February 02, 2021 (last updated February 22, 2025)
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2020-14221
Disclosure Date: February 02, 2021 (last updated November 28, 2024)
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
0
Attacker Value
Unknown
CVE-2020-14222
Disclosure Date: November 05, 2020 (last updated February 22, 2025)
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
0