CyberRota Analysis
AI-GeneratedHCL Aftermarket EPC is vulnerable due to its implementation of a permissive HTML5 cross-origin resource sharing (CORS) policy, allowing unrestricted access from any domain. This flaw could lead to unauthorized data exposure or manipulation by malicious actors. Organizations utilizing this application should prioritize remediation to mitigate potential security risks.
CVE
CVE-2024-23578
Severity
MEDIUM
CVSS
4.2
EPSS
0.12%
Original NVD Description
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).