CVE-2024-42210

A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*

History

23 Mar 2026, 14:16

Type Values Removed Values Added
References
  • () https://github.com/MarioTesoro/vulnerability-research/blob/main/CVE-2024-42210/README.md -

19 Mar 2026, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*
First Time Hcltech unica
Hcltech
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123760 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123760 - Vendor Advisory

19 Mar 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 08:16

Updated : 2026-03-23 14:16


NVD link : CVE-2024-42210

Mitre link : CVE-2024-42210

CVE.ORG link : CVE-2024-42210


JSON object : View

Products Affected

hcltech

  • unica
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')