Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55274

Опубликовано: 26 мар. 2026
Источник: nvd
CVSS3: 2.6
CVSS3: 4.3
EPSS Низкий

Описание

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 8%
0.0018
Низкий

2.6 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-942

Связанные уязвимости

CVSS3: 2.6
github
4 месяца назад

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.

EPSS

Процентиль: 8%
0.0018
Низкий

2.6 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-942