CVE-2025-0272

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 10, 2025
CWE ID 79
CWE ID 80

Summary

CVE-2025-0272 is a vulnerability affecting HCL DevOps Deploy and HCL Launch. The issue involves HTML injection, allowing users to embed arbitrary HTML tags in the Web UI. This vulnerability could potentially result in the disclosure of sensitive information. Attackers might exploit this flaw to execute malicious code or steal data, posing a significant risk to organizations using these products. It is essential to apply the necessary patches to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share