CVE-2025-62320
Estado: AnalizadaMedia (6.1)—
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (9)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-62320",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-62320",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-17T12:56:45.655304Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "HCL",
"product": "Sametime",
"versions": [
{
"status": "affected",
"version": "version 25.1.1 and below."
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-17T13:16:16.503",
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129460",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@hcl.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser."
},
{
"lang": "es",
"value": "La Inyección HTML puede llevarse a cabo en el Producto cuando una aplicación web no verifica o limpia adecuadamente la entrada del usuario antes de mostrarla en una página web. Debido a esto, un atacante puede insertar código HTML no deseado en la página. Cuando el navegador carga la página, puede interactuar automáticamente con recursos externos incluidos en ese HTML, lo que puede causar solicitudes inesperadas desde el navegador del usuario."
}
],
"lastModified": "2026-06-17T09:51:44.057",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "305B2D5D-64DB-40FC-9188-CCF3EA5764F1",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10B800BE-C835-4E99-A05F-FF5B0C8556F3",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_audience_central:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3B128F6-5258-4CD7-9B8B-2EA82575046B",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_audience_central:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56033CC8-1562-481D-9781-68605E639D33",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_campaign:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DBD704E0-EC17-40EF-B125-A3F7B2265C87",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_campaign:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21A943C9-F93D-4385-9FA2-D7970FDF2CF5",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_centralised_offer_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62BA1D1F-E3A6-4F78-98C8-C5BF4C28BB45",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_centralised_offer_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "122EAB2F-BB96-4954-93F9-82FB61D27A5D",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_contact_central:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CB92F37-C4B6-403B-A150-C9BCB094CD41",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_contact_central:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A55CF519-0F7B-469D-96FE-D29DEDC35C9C",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_interact:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "23118E78-677A-4E04-ABAA-7A301B45FFB1",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_interact:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73B4E36F-D53D-4E3C-92DA-97151A2BCEDF",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_journey:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7802A1C-BE9A-45BB-81EE-C1836BB6933C",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_journey:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "206F9793-8910-45B1-8249-B3F04B326AB2",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_plan:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D193791-017A-4E65-A183-4780E3DE37AE",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_plan:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2EDC3A16-B40C-44D0-BEDB-8EBEE9671B58",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_segment_central:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13A74D83-78CC-495E-AC56-90C472725477",
"versionEndExcluding": "12.1.11"
},
{
"criteria": "cpe:2.3:a:hcltech:unica_segment_central:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C9D635D-AB51-43CF-B5C5-6E013191A637",
"versionEndExcluding": "25.1.1.0.1",
"versionStartIncluding": "25.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@hcl.com"
}