CVE-2025-62320: Hcltech Unica
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.
Affected products
- Hcltech Unica: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Audience Central: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Campaign: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Centralised Offer Management: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Contact Central: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Interact: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Journey: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Plan: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
- Hcltech Unica Segment Central: before 12.1.11 (fixed in 12.1.11); from 25.1.0, before 25.1.1.0.1 (fixed in 25.1.1.0.1)
Published 2026-03-17. Last modified 2026-06-17.