Bypass of Script Allowlist in HCL AION
CVE-2025-52624
5.4MEDIUM
What is CVE-2025-52624?
The vulnerability in HCL AION arises from an improperly configured Content-Security-Policy header, which may permit unauthorized scripts to be executed. This misconfiguration heightens the vulnerability to cross-site scripting (XSS) and other injection-based attacks, potentially leading to unauthorized data access or manipulation. Specifically, this issue affects version 2.0 of HCL AION, emphasizing the critical importance of proper security configuration in safeguarding web applications.
Affected Version(s)
AION 2.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved