3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
Basic Information
ID
CVE-2025-52609
Source
HCL
Published
Jun 4, 2026 at 11:42
Affected Product
Vendor
HCL
Product
iControl
Version
4.0.0
Affected Versions
HCL iControl 4.0.0