CVE-2025-52656High· 7.6▾ TwilightHCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields.
dryice_myxalytics = 6.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-52658Low· 3.5HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.
CVE-2025-52654Medium· 4.6HCL MyXalytics v6.6 is affected by an HTML Injection
CVE-2025-52653High· 7.6HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application
CVE-2026-32640Critical· 9.8SimpleEval is a library for adding evaluatable expressions into python projects
CVE-2022-27545Medium· 4.6BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2022-27544Medium· 5.0BigFix Web Reports authorized users may see SMTP credentials in clear text.