SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23567

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable due to the exposure of sensitive information through GET method requests and URL parameters, which can inadvertently store data in server logs, browser history, and proxy logs. This could lead to unauthorized access to confidential information. Organizations using this application should prioritize addressing this vulnerability to mitigate potential data leaks.

CVE
CVE-2024-23567
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.