CVE-2024-30155
—CVSS 3.1
4.3 medium
EPSS
<1%p12
Published
()
Modified
Description
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
- Vendors
- hcltech
- Products
- hcl sx
- Weakness
- CWE-1275
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.