Description
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.
Problem types
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Product status
12.1.10 - 25.1
References
support.hcl-software.com/...rticle&sysparm_article=KB0124424