HCL iControl是印度HCL公司的一个IT基础设施监控与自动化运维平台。 HCL iControl存在安全漏洞,该漏洞源于导出CSV时存在CSV注入,由于输入参数清理不足,可能导致反射型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59874 | 8.1 HIGH | HCL Hive Telco Observability is affected by a Required directives missing from the CSP . |
| CVE-2025-52606 | 4.3 MEDIUM | HCL iControl was affected by Weak Input Validation vulnerability. . |
| CVE-2025-52609 | 3.7 LOW | HCL iControl was affected by Missing Security Headers vulnerability. |
| CVE-2025-52611 | 3.1 LOW | HCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerability |
| CVE-2025-52608 | 3.1 LOW | HCL iControl was affected by Missing Cookie Attributes vulnerability. |
No comments yet