SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23570

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable to clickjacking due to Cross-Frame Scripting, allowing attackers to embed the application in a malicious iFrame. This can lead to various security risks, including phishing, Cross-Site Request Forgery, and potential leakage of sensitive information. Organizations using this application should prioritize addressing this vulnerability to mitigate the associated risks.

CVE
CVE-2024-23570
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.