CVE-2025-52629: HCL AION is susceptible to Missing Content-Security-Policy
HCL AION is susceptible to Missing Content-Security-Policy.
An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to execute..This issue affects AION: 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52629?
The severity of CVE-2025-52629 is considered moderate due to the risk of cross-site scripting and content injection attacks.
How do I fix CVE-2025-52629?
To fix CVE-2025-52629, implement a Content-Security-Policy header to control the sources of content that can be loaded.
What are the potential impacts of CVE-2025-52629?
The potential impacts of CVE-2025-52629 include increased vulnerability to cross-site scripting attacks and unauthorized resource execution.
Is CVE-2025-52629 applicable to all versions of HCL AION?
CVE-2025-52629 is applicable to all versions of HCL AION that do not implement a Content-Security-Policy header.
What should I do if I cannot implement a Content-Security-Policy for CVE-2025-52629?
If you cannot implement a Content-Security-Policy for CVE-2025-52629, ensure to validate and sanitize user inputs and limit the use of external resources.