Medium severity4.6NVD Advisory· Published Apr 2, 2023· Updated Jun 17, 2026
CVE-2022-42452
CVE-2022-42452
Description
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
Affected products
4cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*range: >=6.2.0.0,<=6.2.7.18
- cpe:2.3:a:hcltechsw:hcl_launch:7.3.0.0:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: < 6.2.7.18, 7.0 -7.0.5.13, 7.1-7.1.2.9, 7.2-7.2.3.2, 7.3
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.