GHSA-5wg4-rfc2-hgh3
GitHub Security Advisory
⚠ Unreviewed
LOW
Has CVE
Advisory Details
The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: September 13, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.