CVE-2025-31994

Publication date

2025-10-13 03:59:01

Family

HCL

State

PUBLISHED

Description

HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the servers immediate response to the victims browser, executing the script as if it originated from the trusted website.