Security Advisory

CVE-2021-27778

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-05-31 23:50:11
Last updated 2024-09-17 00:06:06
Assigner HCL
State PUBLISHED

Description

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.