Vulnerability XSS in Digital Experience

Note from the moderator:

This issue has been reported to HCLSoftware Product Security Incident Report (HCL PSIRT team) at:
https://www.hcl-software.com/resources/psirt

Meanwhile we have removed the content here since this is not the proper forum for reporting potential vulnerabilities. In the future, if you have an HCL Support contract, please open a case. If not, you can reach out to the HCL PSIRT team.

Hello Damiano,

Do you have a security report that was generated for this suspected vulnerability? Does the report include a CVE number? The vulnerability number will help in providing specific documentation for you.

I would also suggest the following article:

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0088223

That makes reference to the security hardening guide and ensuring your environment has applied the latest cumulative fixes available.

Finally, If the further immediate information is required. Please open a case with the HCL DX Support team.

Thank you

Mike

yes we have a report, the suspected vulnerability is classified CWE-79

Notice also that the payload not inserted into the DOM but is in JSON. The relevant special character is escaped - " becomes \", so the integrity of the string is maintained in that context. The onus would be on any code which reads this JSON and inserts this string into markup to HTML-encode it.

Also, this is not the proper forum for reporting potential vulnerabilities. In the future, if you have an HCL Support contract, please open a case. If not, you can reach out to the HCL PSIRT team per:

https://www.hcl-software.com/resources/psirt