← back
CVE-2025-52660lowCWE-644

HCL AION is affected by an Host Header Injection vulnerability

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 2.7epss 0.3%
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products
HCL Software · AION