CVE-2025-52603
Low
|3.5No Exploit
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to access limited internal information from HCL Connections if they navigate the system in a specific way. However, the attacker must have access to the application and follow a particular sequence of actions to exploit this issue.
Technical Description
HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$458($100-$500)
Vendor Response
Grade APatched in 0 days
Quick Information
Published
Feb 20, 2026
about 2 months ago
Last Modified
Feb 20, 2026
about 2 months ago
Vendor
hcltech
Product
connections