CVE-2025-52652
Received Received - Intake

Content Spoofing in HCL MyXalytics

Vulnerability report for CVE-2025-52652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: HCL Software

Description

HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl myxalytics *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL MyXalytics is affected by a Content Spoofing Vulnerability. This flaw allows an attacker to manipulate the content displayed to users, making it appear as if it comes from a trusted source. This could be used for phishing attacks or to deceive users into sharing sensitive information.

Impact Analysis

This vulnerability could trick you into believing fake messages or alerts are legitimate, leading to phishing attempts or unintended data disclosure. Attackers might impersonate trusted entities to steal credentials or sensitive information.

Compliance Impact

The vulnerability may allow attackers to manipulate displayed content, potentially leading to phishing or data theft. This could compromise data integrity and user trust, which are critical for compliance with GDPR and HIPAA. However, specific compliance impacts are not detailed in the provided context.

Mitigation Strategies

Update HCL MyXalytics to the latest patched version immediately to address the content spoofing vulnerability. Monitor network traffic for suspicious activity and educate users to verify the authenticity of displayed content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-52652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart