📦 Hcl Compass

by Hcltech

🔍 What is Hcl Compass?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-37502

CRITICAL CVSS 9.0 Oct 18, 2023

HCL Compass has an unrestricted file upload vulnerability that allows attackers to upload malicious files containing executable code. This could lead to remote code execution on the server or client-s...

CVE-2022-42447

CRITICAL CVSS 9.6 Apr 2, 2023

HCL Compass has a Cross-Origin Resource Sharing (CORS) vulnerability that allows attackers to trick authenticated users into making unauthorized requests to the application. This affects all HCL Compa...

CVE-2023-37503

HIGH CVSS 8.1 Oct 19, 2023

HCL Compass has weak password requirements that allow attackers to easily guess passwords and compromise user accounts. This affects all HCL Compass installations with default or weak password policie...

CVE-2023-37504

HIGH CVSS 7.1 Oct 19, 2023

HCL Compass fails to properly invalidate user sessions upon logout, allowing session hijacking. Attackers who obtain valid session identifiers can reuse them to impersonate authenticated users. This a...