CVE-2025-52624
EUVD-2025-3369910.10.2025, 11:15
A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltech | aion | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration