CVE-2025-52612: HCL iControl was affected by Export CSV - CSV Injection vulnerability.
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the Export CSV feature if it is not required to eliminate the CSV injection attack surface.
HCL iControl Export CSV = disabled - Configuration
Implement proper input validation and sanitize or escape user-supplied input before including it in CSV exports to prevent CSV injection (and reflected XSS) caused by insufficient sanitation of input parameters.
HCL iControl input handling input_sanitization / CSV output escaping = enable/implement - Compensating control
Restrict access to CSV export functionality to trusted users or IP ranges and/or deploy WAF rules or filtering to block suspicious payloads that could be used for CSV injection.
- Operational
Audit logs and previously exported CSV files for signs of CSV injection or reflected XSS exploitation and remediate any affected data or accounts.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52612?
CVE-2025-52612 has a severity rating of 7.1, classified as high.
What is CVE-2025-52612 related to?
CVE-2025-52612 refers to a CSV Injection vulnerability in HCL iControl.
How do I fix CVE-2025-52612?
To fix CVE-2025-52612, ensure proper sanitation of input parameters before processing CSV exports.
What is the impact of CVE-2025-52612?
CVE-2025-52612 can potentially allow attackers to perform reflected cross-site scripting attacks.
Which software is affected by CVE-2025-52612?
CVE-2025-52612 affects the HCL iControl software.