CVE-2025-52654

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:dryice_myxalytics:6.6:*:*:*:*:*:*:*

History

10 Oct 2025, 14:15

Type Values Removed Values Added
Summary (en) A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6. (en) HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.

08 Oct 2025, 16:50

Type Values Removed Values Added
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124411 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124411 - Vendor Advisory
CPE cpe:2.3:a:hcltech:dryice_myxalytics:6.6:*:*:*:*:*:*:*
First Time Hcltech
Hcltech dryice Myxalytics

03 Oct 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-03 19:15

Updated : 2025-10-10 14:15


NVD link : CVE-2025-52654

Mitre link : CVE-2025-52654

CVE.ORG link : CVE-2025-52654


JSON object : View

Products Affected

hcltech

  • dryice_myxalytics
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)