Executive brief
HCL Unica and related marketing automation products are vulnerable to a security flaw where malicious code can be injected into web pages. An attacker could use this to trick a user's browser into making unauthorized requests to external servers, potentially leading to the theft of sensitive information. This could impact business operations by compromising user sessions or damaging the reputation of the marketing platform.
Technical details
A vulnerability classified as HTML Injection (related to CWE-79) exists in several HCL Software products, including Unica and Campaign, due to improper neutralization of user-supplied input before it is rendered on a web page. An unauthenticated remote attacker can exploit this by convincing a user to visit a specially crafted link or page, leading to the execution of arbitrary HTML in the victim's browser context. This can be leveraged to perform data exfiltration by forcing the browser to interact with attacker-controlled external resources. The vulnerability is present in versions up to and including 25.1.1, and patches are available via HCL customer support.
Affected products
- HCL Software Unica up to and including 25.1.1
- HCL Software Campaign up to and including 25.1.1
- HCL Software Interact up to and including 25.1.1
- HCL Software Unica Journey up to and including 25.1.1
- HCL Software Unica Plan up to and including 25.1.1
Timeline
- 2026-03-17: disclosed
- 2026-03-17: advisory: HCL Software published security bulletin KB0129460