CVE-2025-52654

MEDIUM

Hcltech Dryice Myxalytics - Basic XSS

Title source: rule
STIX 2.1

Description

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.

Scores

CVSS v3 4.6
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80
Status published
Products (1)
hcltech/dryice_myxalytics 6.6
Published Oct 03, 2025
Tracked Since Feb 18, 2026