High severity8.3NVD Advisory· Published Nov 4, 2022· Updated Jun 17, 2026
CVE-2022-38660
CVE-2022-38660
Description
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
Affected products
10cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*range: <9.0.1
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_3:*:*:*:*:*:*
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_4:*:*:*:*:*:*
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_5:*:*:*:*:*:*
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8:*:*:*:*:*:*
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_1:*:*:*:*:*:*
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_2:*:*:*:*:*:*
- cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_3:*:*:*:*:*:*
- Range: v9
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.