CVE-2025-31969Medium· 4.0▾ SunlitHCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
unica <= 25.1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-52614Low· 3.5HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability
CVE-2025-52615Low· 3.5HCL Unica Platform is impacted by misconfigured security related HTTP headers
CVE-2025-52616Medium· 5.3HCL Unica 12.1.10 can expose sensitive system information
CVE-2025-31996Medium· 5.3HCL Unica Platform is affected by unprotected files due to improper access controls
CVE-2025-31983Low· 3.7HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
CVE-2025-31970Medium· 5.3HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection v…