JavaScript Hijacking Vulnerability in HCL AION by HCL Technologies
CVE-2025-62318

3.7LOW

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2025-62318?

HCL AION contains a vulnerability that allows attackers to exploit JavaScript responses containing sensitive data by referencing them from unauthorized external pages. This can lead to the potential capture of sensitive information by malicious actors, especially when certain conditions are met, thereby posing significant security risks to users.

Affected Version(s)

AION v2.1.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.