PT-2026-28298 · Hcl · Hcl Aftermarket Dpc
CVE-2025-55273
·
Publicado
2026-03-26
·
Atualizado
2026-03-29
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HCL Aftermarket DPC (affected versions not specified)
Description
HCL Aftermarket DPC is susceptible to a Cross Domain Script Include issue. An attacker can use external scripts to manipulate the Document Object Model (DOM), potentially changing the application's content or behavior. This manipulation could allow malicious scripts to steal cookies or session tokens, leading to session hijacking.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hcl Aftermarket Dpc