CVE-2025-31969

MEDIUM

HCL Unica < 25.1.0 - Content Security Policy Misconfiguration

Title source: llm
STIX 2.1

Description

HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.

References (1)

Core 1

Scores

CVSS v3 4.0
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-358
Status published
Products (1)
hcltech/unica < 25.1.0
Published Oct 12, 2025
Tracked Since Feb 18, 2026