ZeroHour

CVE-2024-30155

CVSS 3.1
4.3 medium
EPSS
<1%p12
Published
()
Modified
Description

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

Vendors
hcltech
Products
hcl sx
Weakness
CWE-1275
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.