CVE-2025-55273

HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:*

History

26 Mar 2026, 20:30

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:*
First Time Hcltech
Hcltech aftermarket Cloud
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129793 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129793 - Vendor Advisory

26 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 13:16

Updated : 2026-03-26 20:30


NVD link : CVE-2025-55273

Mitre link : CVE-2025-55273

CVE.ORG link : CVE-2025-55273


JSON object : View

Products Affected

hcltech

  • aftermarket_cloud
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere