VYPR

iControl

by HCL Software

CVEs (5)

  • CVE-2025-52612HigJun 4, 2026
    risk 0.46cvss 7.1epss

    HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .

  • CVE-2025-52606MedJun 4, 2026
    risk 0.28cvss 4.3epss

    HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is…

  • CVE-2025-52609LowJun 4, 2026
    risk 0.24cvss 3.7epss

    HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.

  • CVE-2025-52611LowJun 4, 2026
    risk 0.20cvss 3.1epss

    HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object…

  • CVE-2025-52608LowJun 4, 2026
    risk 0.20cvss 3.1epss

    HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.