Loading HuntDB...

GHSA-5wg4-rfc2-hgh3

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Related CVEs

Key Information

GHSA ID
GHSA-5wg4-rfc2-hgh3
Published
May 24, 2022 5:10 PM
Last Modified
May 24, 2022 5:10 PM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.