The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations. | |
| Title | HCL Verse for Android is susceptible to an injection vulnerability | |
| Weaknesses | CWE-20 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-06-19T14:50:02.931Z
Reserved: 2026-01-05T16:07:58.367Z
Link: CVE-2026-21768
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-19T21:00:04Z