HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-17 14:17
Updated : 2026-07-17 17:56
NVD link : CVE-2024-23578
Mitre link : CVE-2024-23578
CVE.ORG link : CVE-2024-23578
JSON object : View
Products Affected
No product.
CWE
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
