CVE-2023-37511
HCL Traveler To Do is affected by App Transport Security (ATS) settings allowing insecure loads in web content
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Aug 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Affected products
HCL Software · HCL Traveler To DoWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →