CVE-2024-42210
MEDIUM WAF: High
CVSS 5.4
Published: 2026-03-19
CWE-79
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.
WAF Coverage Analysis
Cross-Site Scripting (XSS)
High WAF Coverage
OWASP: A03:2021 Injection
941xxx - XSS / XXE
Affected Software
| Vendor | Product | Version |
|---|---|---|
| hcltech | unica | up to 12.1.9 |
References
- support.hcl-software.com (Vendor Advisory)