CVE-2025-63401: XSS
Published Dec 3, 2025
·Updated
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
Affected Software
2 affected components
HCL Technologies HCLTech DRAGON<7.6.0
hcltech DRAGON<7.6.0
Event History
Dec 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63401?
CVE-2025-63401 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-63401?
To mitigate CVE-2025-63401, upgrade HCLTech DRAGON to version 7.6.0 or later to patch the vulnerability.
3
What type of vulnerability is CVE-2025-63401?
CVE-2025-63401 is a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2025-63401?
CVE-2025-63401 affects users of HCL Technologies Limited HCLTech DRAGON versions before 7.6.0.
5
Can CVE-2025-63401 be exploited remotely?
Yes, CVE-2025-63401 can be exploited by a remote attacker to execute arbitrary code.