PT-2025-48976 · Hcltech · Hcltech Dragon

Published

2025-12-03

·

Updated

2025-12-03

·

CVE-2025-63401

CVSS v3.1

5.5

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions HCLTech DRAGON versions prior to 7.6.0
Description A Cross Site Scripting issue exists in HCLTech DRAGON. This allows a remote attacker to potentially execute arbitrary code due to missing directives.
Recommendations Update HCLTech DRAGON to version 7.6.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63401

Affected Products

Hcltech Dragon