Vulnerability Description
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Unica | < 12.1.9 |
Related Weaknesses (CWE)
References
- https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123760Vendor Advisory
- https://github.com/MarioTesoro/vulnerability-research/blob/main/CVE-2024-42210/R
FAQ
What is CVE-2024-42210?
CVE-2024-42210 is a vulnerability with a CVSS score of 7.6 (HIGH). A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an a...
How severe is CVE-2024-42210?
CVE-2024-42210 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42210?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Unica.