Vulnerability Details CVE-2022-42452
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.5%
CVSS Severity
CVSS v3 Score 4.6
Products affected by CVE-2022-42452
-
cpe:2.3:a:hcltechsw:hcl_launch:6.2.0.0
-
cpe:2.3:a:hcltechsw:hcl_launch:6.2.7.18
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.10
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.11
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.12
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.13
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.0.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.0.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.0.3
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.1.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.1.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.1.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.3
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.4
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.5
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.6
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.7
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.8
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.9
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.0.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.0.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.0.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.1.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.1.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.1.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.2.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.3.0.0