Executive brief
HCL iControl is affected by a security flaw in its CSV export functionality. An attacker could use this to inject malicious content that executes when a user opens an exported file or interacts with the web interface. This could lead to unauthorized access to sensitive data or the compromise of user accounts.
Technical details
HCL iControl contains a vulnerability classified as CWE-1236 (Improper Neutralization of Formula Elements in a CSV File) and reflected cross-site scripting (XSS). The root cause is insufficient sanitation of input parameters that are later included in exported CSV files or reflected in the web interface. An authenticated attacker with low privileges can exploit this by injecting malicious formulas or scripts. Successful exploitation requires a victim to perform an action, such as opening a malicious CSV file in a spreadsheet application or clicking a crafted link, potentially leading to full compromise of confidentiality, integrity, and availability.
Affected products
- HCL iControl
Timeline
- 2026-06-04: advisory: Initial disclosure by HCL Software