allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
As a part of HCL MyXalytics v6.7, these issues have been remediated. For customers using older versions, the mitigation path will include upgrade to version 6.7 which in turn will fix the vulnerabilities during upgrade process. For fix implementation, our HCL MyXalytics support team will provide required the assistance.
Workaround
No workaround given by the vendor.
Fri, 10 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 10 Oct 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure. | |
Title | HCL MyXalytics is affected by a Cross-Domain Script Include vulnerability. | |
Weaknesses | CWE-829 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-10-10T13:46:15.359Z
Reserved: 2025-06-18T14:03:06.891Z
Link: CVE-2025-52655

Updated: 2025-10-10T13:46:12.470Z

Status : Received
Published: 2025-10-10T09:15:37.593
Modified: 2025-10-10T09:15:37.593
Link: CVE-2025-52655

No data.

No data.