CVE-2025-31994

medium

Description

HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website.

References

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124472

Details

Source: Mitre, NVD

Published: 2025-10-13

Updated: 2025-10-14

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00031