CVE-2021-27778

MEDIUM

HCL Traveler < 12.0.1.0 - Stored Cross-Site Scripting via Approved Applications Name Parameter

Title source: llm
STIX 2.1

Description

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

References (1)

Core 1
Core References

Scores

CVSS v3 4.9
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L

Details

CWE
CWE-79
Status published
Products (1)
hcltech/traveler < 12.0.1.0
Published Jun 01, 2022
Tracked Since Feb 18, 2026