CVE-2024-23567
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.31%
- CWE
- CWE-804
- Published
- 2026-07-17
- Last modified
- 2026-07-17
Affected products
- HCLSoftware Aftermarket EPC
Weakness type
Related vulnerabilities
- CVE-2024-23566 — HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha...
- CVE-2026-13082 — GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
- CVE-2026-49953 — Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set
- CVE-2026-40935 — WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- CVE-2026-27411 — WordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerability
- CVE-2025-10423 — newbee-mall kaptcha mallKaptcha Captcha
- CVE-2025-8546 — atjiu pybbs Verification Code login Captcha
- CVE-2025-40916 — Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha text