Junglewise Threat Intelligence

CVE-2025-63401: HCL Technologies HCLTech DRAGON cross-site scripting

CVE-2025-63401 · Severity: medium · CVSS 5.5 · Published 2025-12-03

Executive brief

HCLTech DRAGON, a technology platform used for enterprise digital transformation, is affected by a security vulnerability that could allow an attacker to execute unauthorized code. By exploiting missing security directives, a remote attacker with high-level privileges could potentially compromise the integrity of the system or access sensitive information. This issue is resolved in version 7.6.0.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in HCLTech DRAGON versions prior to 7.6.0. The flaw is rooted in the absence of proper security directives, which allows a remote attacker to inject and execute arbitrary code. Exploitation requires the attacker to have high privileges (PR:H) and involves a high level of complexity (AC:H). The vulnerability is tracked as CWE-79 and has been addressed in the v.7.6.0 release.

Affected products

  • HCL Technologies DRAGON before 7.6.0

Timeline

  • 2025-12-03: advisory
  • 2025-12-03: disclosed

References