HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
CVE ID: CVE-2023-28017
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.4
Vendor: HCL Software
Product: HCL Connections
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 23.71% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)