← Back

Connections

connections

Vendor: Hcltech • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Connections
Jun 17, 2026
Apr 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
1Hcltech
1Connections
Jun 17, 2026
Mar 9, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t...Show more
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Hcltech
1Connections
Jun 17, 2026
Mar 5, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.
1Hcltech
1Connections
Jun 17, 2026
Mar 5, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute...Show more
The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less