CVE-2025-55273: HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55273?
CVE-2025-55273 is identified as a critical vulnerability due to its potential to allow unauthorized script execution.
How do I fix CVE-2025-55273?
To fix CVE-2025-55273, apply the latest security patches provided by HCL for the Aftermarket DPC software.
What can attackers do with CVE-2025-55273?
Attackers can exploit CVE-2025-55273 to manipulate the DOM and execute malicious scripts that may steal sensitive data.
Which software is affected by CVE-2025-55273?
CVE-2025-55273 affects the HCL Aftermarket DPC software.
Is CVE-2025-55273 a known vulnerability?
Yes, CVE-2025-55273 is a publicly identified vulnerability that has been documented and assigned a CVE ID.