Vulnerability Details CVE-2022-42452
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.6%
CVSS Severity
CVSS v3 Score 4.6
Products affected by CVE-2022-42452
-
cpe:2.3:a:hcltechsw:hcl_launch:6.2.0.0
-
cpe:2.3:a:hcltechsw:hcl_launch:6.2.7.18
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.10
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.11
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.12
-
cpe:2.3:a:hcltechsw:hcl_launch:7.0.5.13
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.0.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.0.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.0.3
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.1.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.1.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.1.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.3
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.4
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.5
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.6
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.7
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.8
-
cpe:2.3:a:hcltechsw:hcl_launch:7.1.2.9
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.0.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.0.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.0.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.1.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.1.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.1.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.2.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.0
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.1
-
cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.2
-
cpe:2.3:a:hcltechsw:hcl_launch:7.3.0.0