CVE-2025-52654
Last modified
CVE-2025-52654 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Dryice Myxalytics | 6.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-52654?
How severe is CVE-2025-52654?
How do I fix CVE-2025-52654?
Are you affected by CVE-2025-52654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
