Medium severity5.5NVD Advisory· Published Dec 3, 2025· Updated Jul 5, 2026
CVE-2025-63401
CVE-2025-63401
Description
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<7.6.0+ 1 more
- (no CPE)range: <7.6.0
- (no CPE)range: <7.6.0
Patches
Vulnerability mechanics
References
1- excalibur-hcl.my.salesforce.com/sfc/p/nvdVendor Advisory
News mentions
0No linked articles in our index yet.