HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)
Metrics
Affected Vendors & Products
References
History
Wed, 06 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS) | |
| Title | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability | |
| Weaknesses | CWE-358 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-05-06T10:22:41.866Z
Reserved: 2025-04-01T18:46:23.152Z
Link: CVE-2025-31970
No data.
Status : Received
Published: 2026-05-06T11:16:03.650
Modified: 2026-05-06T11:16:03.650
Link: CVE-2025-31970
No data.
OpenCVE Enrichment
Updated: 2026-05-06T11:30:26Z