CVE-2025-62341

Summary

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareConnections7.0, 8.0affected

Weaknesses

  • CWE-918: CWE-918 Server-Side request forgery (SSRF)

References