HCL Unica是印度HCL公司的一个企业级营销自动化与活动管理平台。 HCL Unica 12.1.10版本存在安全漏洞,该漏洞源于可能暴露敏感系统信息,攻击者可利用这些信息制定攻击计划。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | Unica | <=12.1.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-31992 | 4.6 MEDIUM | HCL MaxAI Assistant is susceptible to a HTML injection vulnerability |
| CVE-2025-31997 | 4.2 MEDIUM | HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References |
| CVE-2025-31969 | 4.0 MEDIUM | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP) |
| CVE-2025-52615 | 3.5 LOW | HCL Unica Platform is impacted by misconfigured security related HTTP headers |
| CVE-2025-52614 | 3.5 LOW | HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability |
| CVE-2025-31998 | 3.5 LOW | HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which ex |
| CVE-2025-31993 | 3.5 LOW | HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Fo |
No comments yet