CVE-2025-62320Disclosure(hcltech / unica)

LOWCVSS 6.1 · MEDIUM

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unica
  • unica_audience_central
  • unica_campaign
  • unica_centralised_offer_management

Threat summary

  • 7 mentions across 1 observed day

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • 7 total mentions across 1 day

Affected systems

Vendors
Products
unicaunica_audience_centralunica_campaignunica_centralised_offer_managementunica_contact_centralunica_interactunica_journeyunica_planunica_segment_central

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-03-17: 7Technical Details · 2026-03-17: 603-17
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets8 URLs
Full discourse7 posts
  • CVE@CVEnew
    General

    CVE-2025-62320 HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an at… https://www.cve.org/CVERecord?id=CVE-2025-62320

    Post summary

    The post briefly notes the existence of CVE‑2025‑62320 as an HTML Injection flaw but offers no additional technical, exploit, or mitigation details.

    00000141
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-62320 📊 Severity: 4.7 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-62320 #CVE-2025-62320 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/kl0NuO55ox

    Post summary

    The tweet announces CVE-2025-62320, noting its medium severity and unspecified affected products, but offers no technical details, exploits, or mitigation guidance.

    00000107
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-62320 - HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform Intel Report: https://ift.tt/tusvpzc

    Post summary

    The tweet announces CVE‑2025‑62320, an HTML injection flaw in HCL Unica Platform that can enable data exfiltration, but provides no PoC, exploit, or patch information.

    00000113
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-62320 - HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform Intel Report: https://ift.tt/ryPTGzt

    Post summary

    The post announces the HTML injection vulnerability CVE-2025-62320 affecting HCL Unica Platform, noting potential data exfiltration, and links to an intel report, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000139
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-62320 - HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform Intel Report: https://ift.tt/cM9JjxG

    Post summary

    The alert announces CVE-2025-62320, an HTML injection that allows data exfiltration from HCL Unica Platform, and points to an Intel report but does not provide PoC, exploit, or patch details.

    00000101
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-62320 - HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica Platform Intel Report: https://ift.tt/YoA4gPq

    Post summary

    The post announces CVE-2025-62320 affecting HCL Unica Platform, describing an HTML injection that can exfiltrate data, and links to an intel report, without providing a PoC, exploit tool, or patch information.

    0000095
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-62320 HTML Injection Vulnerability in Web Application via Unvalidated User Inp... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-62320 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE-2025-62320 as an HTML injection flaw caused by unvalidated user input, linking to vulnerability details but providing no PoC, exploit, or mitigation.

    0000065
    4.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Apphcltechunica---
Apphcltechunica_audience_central---
Apphcltechunica_campaign---
Apphcltechunica_centralised_offer_management---
Apphcltechunica_contact_central---
Apphcltechunica_interact---
Apphcltechunica_journey---
Apphcltechunica_plan---
Apphcltechunica_segment_central---

Explore more