HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser. | |
| Title | HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-03-17T12:56:51.604Z
Reserved: 2025-10-10T09:04:19.898Z
Link: CVE-2025-62320
Updated: 2026-03-17T12:56:48.535Z
Status : Awaiting Analysis
Published: 2026-03-17T13:16:16.503
Modified: 2026-03-17T14:20:01.670
Link: CVE-2025-62320
No data.
OpenCVE Enrichment
No data.