Critical severity9.0NVD Advisory· Published Oct 18, 2023· Updated Jun 17, 2026
CVE-2023-37502
CVE-2023-37502
Description
HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
Affected products
4cpe:2.3:a:hcltech:hcl_compass:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hcltech:hcl_compass:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.0.3
- cpe:2.3:a:hcltech:hcl_compass:2.1.0:*:*:*:*:*:*:*
- Range: 2.0, 2.1, 2.2
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.