We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-0272

HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability



Description

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

Reserved 2025-01-06 | Published 2025-04-03 | Updated 2025-04-04 | Assigner HCL


MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

Default status
unaffected

7.0 - 7.0.5.26; 7.1 - 7.1.2.21; 7.2 - 7.2.3.14; 7.3 - 7.3.2.9; 8.0 - 8.0.1.4; 8.1 - 8.1.0.0
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0120137

cve.org (CVE-2025-0272)

nvd.nist.gov (CVE-2025-0272)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-0272

Support options

Helpdesk Chat, Email, Knowledgebase