CVE-2025-62320
Last modified
CVE-2025-62320 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Unica | < 12.1.11 |
| Hcltech | Unica | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Audience Central | < 12.1.11 |
| Hcltech | Unica Audience Central | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Campaign | < 12.1.11 |
| Hcltech | Unica Campaign | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Centralised Offer Management | < 12.1.11 |
| Hcltech | Unica Centralised Offer Management | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Contact Central | < 12.1.11 |
| Hcltech | Unica Contact Central | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Interact | < 12.1.11 |
| Hcltech | Unica Interact | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Journey | < 12.1.11 |
| Hcltech | Unica Journey | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Plan | < 12.1.11 |
| Hcltech | Unica Plan | >= 25.1.0, < 25.1.1.0.1 |
| Hcltech | Unica Segment Central | < 12.1.11 |
| Hcltech | Unica Segment Central | >= 25.1.0, < 25.1.1.0.1 |
References
- https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129460Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-62320?
How severe is CVE-2025-62320?
How do I fix CVE-2025-62320?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62312HCL AION is affected by a vulnerability where basic authoriz…3
- CVE-2025-62313HCL AION is affected by a vulnerability where adequate prote…5.4
- CVE-2025-62316HCL AION is affected by a vulnerability where certain securi…2.3
- CVE-2025-62317HCL AION is affected by a vulnerability where sensitive info…2.6
- CVE-2025-62319Boolean-Based SQL Injection is a type of blind SQL injection…9.8
- CVE-2025-6232An improper validation vulnerability was reported in Lenovo …8.5
- CVE-2025-62326HCL Digital Experience is susceptible to stored cross-site s…4.8
- CVE-2025-62327In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LL…4.9
- CVE-2025-62328HCL Nomad server on Domino did not configure the frame-ances…3.7
- CVE-2025-62329HCL DevOps Deploy / HCL Launch is susceptible to a race cond…5.6
- CVE-2025-6233Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5…4.9
- CVE-2025-62330HCL DevOps Deploy is susceptible to a cleartext transmission…5.9
Are you affected by CVE-2025-62320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
