Cross Site Scripting Vulnerability in HCL MyXalytics Web Application
CVE-2025-52653

7.6HIGH

Key Information:

Vendor
CVE Published:
3 October 2025

What is CVE-2025-52653?

The HCL MyXalytics product contains a Cross Site Scripting vulnerability that may allow attackers to inject and execute unauthorized scripts within the web application. This can lead to unauthorized actions or potentially grant malicious users access to sensitive data or perform unwanted operations on behalf of authenticated users. Ensuring that your software is updated and secure is critical to mitigating risks associated with this type of vulnerability.

Affected Version(s)

HCL MyXalytics 6.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52653 : Cross Site Scripting Vulnerability in HCL MyXalytics Web Application