4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
Basic Information
ID
CVE-2025-55273
Source
HCL
Published
Mar 26, 2026 at 12:52
Modified
Mar 26, 2026 at 15:01
Affected Product
Vendor
HCL
Product
Aftermarket DPC
Version
version 1.0.0
Affected Versions
HCL Aftermarket DPC version 1.0.0