CVE 4.3 MEDIUM

HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability_CVE-2025-55273

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.

Basic Information

ID CVE-2025-55273
Source HCL
Published Mar 26, 2026 at 12:52
Modified Mar 26, 2026 at 15:01

Affected Product

Vendor HCL
Product Aftermarket DPC
Version version 1.0.0
Affected Versions HCL Aftermarket DPC version 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.