CVE-2025-52612: Hcltech Icontrol

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .

Affected products

  • Hcltech Icontrol: version 4.0.0 only

Published 2026-06-04. Last modified 2026-07-22.