CVE-2025-31969

MEDIUM

Hcltech Unica < 25.1.0 - XSS

Title source: rule
STIX 2.1

Description

HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.

Scores

CVSS v3 4.0
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-358
Status published
Products (1)
hcltech/unica < 25.1.0
Published Oct 12, 2025
Tracked Since Feb 18, 2026