{"id":"CVE-2025-52652","title":"HCL MyXalytics was affected by Content Spoofing Vulnerability","summary":"HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-451"],"vendor":"HCL Software","product":"MyXalytics","affected":["MyXalytics v6.6, v6.7, v6.8 and v6.8.0.1"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T16:17:50.420","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-52652","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132828","label":"psirt@hcl.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T15:22:43.455935Z"},"epss":0.00147,"epssPercentile":0.04291,"ingestedAt":"2026-09-08T15:33:26.976Z","slug":"CVE-2025-52652","body":"## Overview\n\nHCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}