CVE-2025-52653

7.6

HCL · MyXalytics

HCL MyXalytics is vulnerable to Cross Site Scripting (XSS), which may allow unauthorized script execution within the web application.

Executive summary

A Cross Site Scripting vulnerability in HCL MyXalytics version 6.6 poses a significant risk of unauthorized actions and potential data compromise for authenticated users.

Vulnerability

The application is susceptible to CWE-79, Improper Neutralization of Input During Web Page Generation, which allows low privileged authenticated users to execute unauthorized scripts in the context of the web application.

Business impact

The presence of an XSS vulnerability in a business application can lead to session hijacking, unauthorized actions performed on behalf of legitimate users, and potential exfiltration of sensitive data. Given the CVSS score of 7.6, this flaw is classified as High severity, indicating that while it requires user interaction, the potential for impact on confidentiality and availability is substantial.

Remediation

Immediate Action: Upgrade HCL MyXalytics to version 6.7 to remediate the vulnerability.

Proactive Monitoring: Review web application access and error logs for suspicious patterns, such as unusual script tags or encoded characters in input parameters.

Compensating Controls: Deploy a Web Application Firewall (WAF) with configured XSS protection rules to inspect and filter malicious payloads targeting the application.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the High severity of this vulnerability, administrators should prioritize the upgrade to version 6.7 immediately. Failure to address this flaw leaves the application susceptible to session-based attacks, which can compromise the integrity of the entire user base.

More HCL CVEs

Sources