PT-2026-28298 · Hcl · Hcl Aftermarket Dpc

Published

2026-03-26

·

Updated

2026-03-29

·

CVE-2025-55273

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL Aftermarket DPC (affected versions not specified)
Description HCL Aftermarket DPC is susceptible to a Cross Domain Script Include issue. An attacker can use external scripts to manipulate the Document Object Model (DOM), potentially changing the application's content or behavior. This manipulation could allow malicious scripts to steal cookies or session tokens, leading to session hijacking.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-55273

Affected Products

Hcl Aftermarket Dpc