SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23569

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable due to the absence of the "X-XSS-Protection" header, which can lead to cross-site scripting (XSS) attacks. This vulnerability could allow attackers to execute malicious scripts in the context of the user's session, potentially compromising sensitive data. Organizations utilizing HCL Aftermarket EPC should prioritize remediation to enhance their security posture against XSS threats.

CVE
CVE-2024-23569
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header