A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.

Project Subscriptions

Vendors Products
Hcltech Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech unica
CPEs cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech unica

Thu, 19 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Mar 2026 08:00:00 +0000

Type Values Removed Values Added
Description A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.
Title HCL Unica Marketing Operations v12.1.8 and lower is affected by a Stored cross-site scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-03-19T13:31:12.770Z

Reserved: 2024-07-29T21:32:16.370Z

Link: CVE-2024-42210

cve-icon Vulnrichment

Updated: 2026-03-19T13:31:09.058Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-19T08:16:18.700

Modified: 2026-03-19T18:44:50.493

Link: CVE-2024-42210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses