Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-52624

A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-52624
  • Hcltech » Aion » Version: 2.0
    cpe:2.3:a:hcltech:aion:2.0


Contact Us

Shodan ® - All rights reserved