HCL AION Inline Script Execution Vulnerability in Content Security Policy

Vulnerability

A vulnerability allowing inline script execution has been identified in HCL AION version 2.0. This issue arises from an improperly configured Content Security Policy (CSP) that fails to restrict inline scripts, potentially exposing the application to script-based attacks. The vulnerability was highlighted in a Dynamic Application Security Testing report.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of inline scripts, increasing the risk of cross-site scripting (XSS) attacks and other script-based vulnerabilities.

Remediation

Users can upgrade to HCL AION version 2.0.1, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION Product support team.

Added: Oct 10, 2025, 10:16 AM
Updated: Oct 10, 2025, 10:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
6.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.