« Volver al listado

CVE-2025-62320

Estado: AnalizadaMedia (6.1)—

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (9)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-62320",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-62320",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-17T12:56:45.655304Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@hcl.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "HCL",
          "product": "Sametime",
          "versions": [
            {
              "status": "affected",
              "version": "version 25.1.1 and below."
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-17T13:16:16.503",
  "references": [
    {
      "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129460",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@hcl.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@hcl.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser."
    },
    {
      "lang": "es",
      "value": "La Inyección HTML puede llevarse a cabo en el Producto cuando una aplicación web no verifica o limpia adecuadamente la entrada del usuario antes de mostrarla en una página web. Debido a esto, un atacante puede insertar código HTML no deseado en la página. Cuando el navegador carga la página, puede interactuar automáticamente con recursos externos incluidos en ese HTML, lo que puede causar solicitudes inesperadas desde el navegador del usuario."
    }
  ],
  "lastModified": "2026-06-17T09:51:44.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "305B2D5D-64DB-40FC-9188-CCF3EA5764F1",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10B800BE-C835-4E99-A05F-FF5B0C8556F3",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_audience_central:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3B128F6-5258-4CD7-9B8B-2EA82575046B",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_audience_central:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56033CC8-1562-481D-9781-68605E639D33",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_campaign:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBD704E0-EC17-40EF-B125-A3F7B2265C87",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_campaign:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21A943C9-F93D-4385-9FA2-D7970FDF2CF5",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_centralised_offer_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62BA1D1F-E3A6-4F78-98C8-C5BF4C28BB45",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_centralised_offer_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "122EAB2F-BB96-4954-93F9-82FB61D27A5D",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_contact_central:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CB92F37-C4B6-403B-A150-C9BCB094CD41",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_contact_central:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A55CF519-0F7B-469D-96FE-D29DEDC35C9C",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_interact:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23118E78-677A-4E04-ABAA-7A301B45FFB1",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_interact:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73B4E36F-D53D-4E3C-92DA-97151A2BCEDF",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_journey:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7802A1C-BE9A-45BB-81EE-C1836BB6933C",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_journey:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "206F9793-8910-45B1-8249-B3F04B326AB2",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_plan:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D193791-017A-4E65-A183-4780E3DE37AE",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_plan:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EDC3A16-B40C-44D0-BEDB-8EBEE9671B58",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_segment_central:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13A74D83-78CC-495E-AC56-90C472725477",
              "versionEndExcluding": "12.1.11"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:unica_segment_central:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C9D635D-AB51-43CF-B5C5-6E013191A637",
              "versionEndExcluding": "25.1.1.0.1",
              "versionStartIncluding": "25.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@hcl.com"
}