CVE-2025-52652: HCL MyXalytics is affected by multiple security vulnerabilities.
Published Sep 7, 2026
·Updated
HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.
Affected Software
1 affected component
HCL MyXalytics
Event History
Sep 7, 2026
CVE Published
via MITRE·10:37 AM
Data Sourced
via MITRE·10:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and user interaction are required for exploitation?
An attacker needs low-level privileges and must persuade a user to interact with maliciously manipulated content. The attack can be performed over the network.
2
What is the likely security impact?
The vulnerability affects integrity by allowing displayed content to be manipulated so it appears to come from a trusted source. This could support phishing or attempts to obtain data, while no direct confidentiality or availability impact is identified by the supplied severity vector.