Vendor CVEs
HCL Software
All CVEs
623 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-50351 | Hig | 0.53 | 8.2 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data. | ||
| CVE-2023-50350 | Hig | 0.53 | 8.2 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information. | ||
| CVE-2023-37503 | Hig | 0.53 | 8.1 | 0.00 | Oct 19, 2023 | HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts. | ||
| CVE-2023-37536 | Hig | 0.53 | 8.2 | 0.01 | Oct 11, 2023 | An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | ||
| CVE-2023-37501 | Hig | 0.53 | 8.1 | 0.00 | Aug 3, 2023 | A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user's session and perform other attacks. | ||
| CVE-2023-37500 | Hig | 0.53 | 8.1 | 0.00 | Aug 3, 2023 | A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacker could hijack a user's session and perform other attacks. | ||
| CVE-2023-37499 | Hig | 0.53 | 8.1 | 0.00 | Aug 3, 2023 | A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An attacker could hijack a user's session and perform other attacks. | ||
| CVE-2023-37498 | Hig | 0.53 | 8.1 | 0.01 | Aug 3, 2023 | A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges. | ||
| CVE-2023-37497 | Hig | 0.53 | 8.1 | 0.01 | Aug 3, 2023 | The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service. | ||
| CVE-2022-38657 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page. | ||
| CVE-2021-27771 | Hig | 0.53 | 8.2 | 0.01 | May 12, 2022 | User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when… | ||
| CVE-2020-4125 | Hig | 0.53 | 8.1 | 0.00 | Jul 20, 2020 | Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information. | ||
| CVE-2019-4391 | Hig | 0.53 | 8.2 | 0.01 | Apr 7, 2020 | HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data | ||
| CVE-2023-37537 | Hig | 0.51 | 7.8 | 0.00 | Oct 17, 2023 | An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges. | ||
| CVE-2023-37520 | Hig | 0.50 | 7.7 | 0.00 | Dec 21, 2023 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay. | ||
| CVE-2023-37519 | Hig | 0.50 | 7.7 | 0.00 | Dec 21, 2023 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. | ||
| CVE-2022-38658 | Hig | 0.50 | 7.7 | 0.00 | Dec 24, 2022 | BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data… | ||
| CVE-2026-67103 | Hig | 0.49 | 7.6 | 0.00 | Sep 18, 2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of… | ||
| CVE-2026-21752 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws. | ||
| CVE-2025-68825 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications. | ||
| CVE-2023-37507 | Hig | 0.49 | 7.5 | 0.00 | Jul 21, 2026 | HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | ||
| CVE-2024-42210 | Hig | 0.49 | 7.6 | 0.00 | Mar 19, 2026 | A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data… | ||
| CVE-2025-52656 | Hig | 0.49 | 7.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields. | ||
| CVE-2025-52653 | Hig | 0.49 | 7.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access. | ||
| CVE-2025-0280 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2025 | A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access. | ||
| CVE-2025-31955 | Hig | 0.49 | 7.6 | 0.00 | Jul 24, 2025 | HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system. | ||
| CVE-2023-50341 | Hig | 0.49 | 7.6 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a… | ||
| CVE-2023-45723 | Hig | 0.49 | 7.6 | 0.01 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server. | ||
| CVE-2022-27561 | Hig | 0.49 | 7.5 | 0.00 | Sep 15, 2022 | There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf). | ||
| CVE-2022-27563 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2022 | An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service. | ||
| CVE-2021-27777 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2022 | XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references. | ||
| CVE-2021-27756 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2022 | "TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it." | ||
| CVE-2021-27757 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2022 | " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive… | ||
| CVE-2020-14246 | Hig | 0.49 | 7.5 | 0.01 | Feb 4, 2021 | HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials. | ||
| CVE-2020-14255 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2021 | HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations. | ||
| CVE-2020-14274 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2021 | Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors. | ||
| CVE-2020-14273 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2020 | HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server. | ||
| CVE-2020-14254 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2020 | TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it. | ||
| CVE-2020-14258 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2020 | HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected. | ||
| CVE-2020-14234 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected. | ||
| CVE-2020-14230 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1… | ||
| CVE-2019-4326 | Hig | 0.49 | 7.5 | 0.01 | Oct 6, 2020 | "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header." | ||
| CVE-2019-4327 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files." | ||
| CVE-2026-21751 | Hig | 0.48 | 7.4 | 0.00 | Aug 24, 2026 | HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached. | ||
| CVE-2025-59870 | Hig | 0.48 | 7.4 | 0.00 | Jan 16, 2026 | HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | ||
| CVE-2021-27764 | Hig | 0.48 | 7.4 | 0.01 | May 6, 2022 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) | ||
| CVE-2026-21756 | Hig | 0.47 | 7.2 | 0.00 | Aug 24, 2026 | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments. | ||
| CVE-2025-55263 | Hig | 0.47 | 7.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets. | ||
| CVE-2025-0255 | Hig | 0.47 | 7.2 | 0.01 | Mar 24, 2025 | HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. | ||
| CVE-2025-52612 | Hig | 0.46 | 7.1 | 0.00 | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . |
- risk 0.53cvss 8.2epss 0.00
HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.
- risk 0.53cvss 8.2epss 0.00
HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.
- risk 0.53cvss 8.1epss 0.00
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
- risk 0.53cvss 8.2epss 0.01
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
- risk 0.53cvss 8.1epss 0.00
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user's session and perform other attacks.
- risk 0.53cvss 8.1epss 0.00
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacker could hijack a user's session and perform other attacks.
- risk 0.53cvss 8.1epss 0.00
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An attacker could hijack a user's session and perform other attacks.
- risk 0.53cvss 8.1epss 0.01
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
- risk 0.53cvss 8.1epss 0.01
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
- risk 0.53cvss 8.2epss 0.00
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
- risk 0.53cvss 8.2epss 0.01
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when…
- risk 0.53cvss 8.1epss 0.00
Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.
- risk 0.53cvss 8.2epss 0.01
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
- risk 0.51cvss 7.8epss 0.00
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
- risk 0.50cvss 7.7epss 0.00
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
- risk 0.50cvss 7.7epss 0.00
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
- risk 0.50cvss 7.7epss 0.00
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data…
- risk 0.49cvss 7.6epss 0.00
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of…
- risk 0.49cvss 7.5epss 0.00
HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.
- risk 0.49cvss 7.5epss 0.00
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.
- risk 0.49cvss 7.5epss 0.00
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
- risk 0.49cvss 7.6epss 0.00
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data…
- risk 0.49cvss 7.6epss 0.00
HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields.
- risk 0.49cvss 7.6epss 0.00
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access.
- risk 0.49cvss 7.5epss 0.00
A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
- risk 0.49cvss 7.6epss 0.00
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
- risk 0.49cvss 7.6epss 0.00
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a…
- risk 0.49cvss 7.6epss 0.01
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.
- risk 0.49cvss 7.5epss 0.00
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
- risk 0.49cvss 7.5epss 0.01
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
- risk 0.49cvss 7.5epss 0.01
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.
- risk 0.49cvss 7.5epss 0.01
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
- risk 0.49cvss 7.5epss 0.01
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive…
- risk 0.49cvss 7.5epss 0.01
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.
- risk 0.49cvss 7.5epss 0.01
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.
- risk 0.49cvss 7.5epss 0.01
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.
- risk 0.49cvss 7.5epss 0.01
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.
- risk 0.49cvss 7.5epss 0.01
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
- risk 0.49cvss 7.5epss 0.01
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected.
- risk 0.49cvss 7.5epss 0.01
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.
- risk 0.49cvss 7.5epss 0.01
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1…
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
- risk 0.48cvss 7.4epss 0.00
HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached.
- risk 0.48cvss 7.4epss 0.00
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
- risk 0.48cvss 7.4epss 0.01
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
- risk 0.47cvss 7.2epss 0.00
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
- risk 0.47cvss 7.3epss 0.00
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets.
- risk 0.47cvss 7.2epss 0.01
HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
- risk 0.46cvss 7.1epss 0.00
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
Page 2 of 13