4.3
CVE-2025-55273
- EPSS 0.04%
- Veröffentlicht 26.03.2026 12:52:59
- Zuletzt bearbeitet 26.03.2026 20:30:24
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Aftermarket Cloud Version1.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.106 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| psirt@hcl.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.