VYPR
Medium severity4.6NVD Advisory· Published Apr 2, 2023· Updated Jun 17, 2026

CVE-2022-42452

CVE-2022-42452

Description

HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.

Affected products

4
  • cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*range: >=6.2.0.0,<=6.2.7.18
    • cpe:2.3:a:hcltechsw:hcl_launch:7.3.0.0:*:*:*:*:*:*:*
  • HCL Software/Launchllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: < 6.2.7.18, 7.0 -7.0.5.13, 7.1-7.1.2.9, 7.2-7.2.3.2, 7.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.