4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Description
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
Basic Information
ID
CVE-2025-31988
Source
HCL
Published
Aug 19, 2025 at 18:12
Modified
Aug 19, 2025 at 18:35
Affected Product
Vendor
HCL Software
Product
Digital Experience
Version
8.5, 9.0, 9.5
Affected Versions
HCL Software Digital Experience 8.5, 9.0, 9.5