CVE-2021-27774
22.09.2022, 21:15
User input included in error response, which could be used in a phishing attack.Enginsight
Vendor | Product | Version |
---|---|---|
hcltech | hcl_digital_experience | 8.5 |
hcltech | hcl_digital_experience | 9.0 |
hcltech | hcl_digital_experience | 9.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-209 - Generation of Error Message Containing Sensitive InformationThe software generates an error message that includes sensitive information about its environment, users, or associated data.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.