SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23578

MEDIUM · CVSS 4.2 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable due to its implementation of a permissive HTML5 cross-origin resource sharing (CORS) policy, allowing unrestricted access from any domain. This flaw could lead to unauthorized data exposure or manipulation by malicious actors. Organizations utilizing this application should prioritize remediation to mitigate potential security risks.

CVE
CVE-2024-23578
Severity
MEDIUM
CVSS
4.2
EPSS
0.12%

Original NVD Description

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).