Impact
HCL MyXalytics contains a content spoofing weakness that allows an attacker to alter displayed information so it appears to come from a trusted source. This manipulation can trick users into performing phishing attacks or unknowingly submitting sensitive data, thereby compromising confidentiality and integrity. The vulnerability is classified under CWE-451.
Affected Systems
The affected product is HCL Software’s MyXalytics. No specific version information is provided in the data, so the scope of the issue across releases is unknown.
Risk and Exploitability
The CVSS score of 3.5 indicates a low to moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an attacker to influence the content that a user views, exploitation would typically depend on user interaction or the presence of a compromised content source.
OpenCVE Enrichment