Back to overview

CVE-2026-21768

MEDIUM
6.3
CVSS 3.1
Description
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

Metadata

CVE ID
CVE-2026-21768
State
PUBLISHED
Assigner
HCL
Reserved
2026-01-05 16:07 UTC
Published
2026-06-19 14:50 UTC
Last updated
2026-06-19 14:50 UTC
Primary CWE
CWE-20
CWE-20 Improper input validation
Vendor / Product
HCLSoftware / Verse for Android
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
HCLSoftware Verse for Android 14.5.10
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20 Improper input validation
CWE-79 cna CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Back to overview