Unrated severityNVD Advisory· Published Dec 3, 2025· Updated Dec 3, 2025
CVE-2025-63401
CVE-2025-63401
Description
Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives
Affected products
2<7.6.0+ 1 more
- (no CPE)range: <7.6.0
- (no CPE)range: <7.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- hcl.commitre
- hcltech.commitre
- excalibur-hcl.my.salesforce.com/sfc/p/mitre
News mentions
0No linked articles in our index yet.