CVE-2023-37502: Hcltech Hcl Compass

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.

Affected products

  • Hcltech Hcl Compass: from 2.0.0, up to and including 2.0.3; from 2.2.0, before 2.2.3 (fixed in 2.2.3); version 2.1.0 only

Published 2023-10-18. Last modified 2026-06-17.