cvedb.io
CVE-2025-62320
MEDIUM · CVSS 4.7
EPSS exploitation probability: 0%
Published 2026-03-17T13:16:16.503 · Last modified 2026-06-17T09:51:44.057

Summary

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.

Affected products

hcltech — unica

Does this affect you?

Add your gear to cvedb and we'll alert you only when hcltech ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.