CVE-2025-55273 PUBLISHED

HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability

Assigner: HCL
Reserved: 12.08.2025 Published: 26.03.2026 Updated: 26.03.2026

HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor HCL
Product Aftermarket DPC
Versions Default: unaffected
  • Version version 1.0.0 is affected

References

Problem Types

  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere CWE