CVE-2023-37538: Hcltech Digital Experience
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
Affected products
- Hcltech Digital Experience: version 8.5 only; version 9.0 only; version 9.5 only
Published 2023-10-11. Last modified 2026-06-17.