Lucene search

K
cveHCLCVE-2022-27561
HistorySep 15, 2022 - 10:15 p.m.

CVE-2022-27561

2022-09-1522:15:11
CWE-79
HCL
web.nvd.nist.gov
42
2
cve-2022-27561
nvd
security
hcl traveler
web admin
lotustraveler.nsf

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

22.7%

There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

Affected configurations

Nvd
Node
hcltechtravelerRange<12.0.1.2
VendorProductVersionCPE
hcltechtraveler*cpe:2.3:a:hcltech:traveler:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HCL Traveler",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "12.1.1 and prior"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

22.7%

Related for CVE-2022-27561