ZeroHour

CVE-2025-52608

CVSS 3.1
4.3 medium
EPSS
<1%p1
Published
()
Modified
Description

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

Vendors
hcltech
Products
icontrol
Weakness
CWE-614
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.