Impact
HCL Aftermarket EPC suffers a clickjacking vulnerability that arises from allowing the application to be embedded in an iframe on a malicious site through cross‑frame scripting. This flaw can enable an attacker to trick users into performing unintended actions, to hijack sessions, or to expose sensitive data. The weakness is a classic information exposure issue (CWE‑200).
Affected Systems
The affected system is HCLSoftware's Aftermarket EPC. No specific version numbers are supplied, so all currently deployed instances of this product are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in the moderate range, and the EPSS score of less than 1 % indicates a low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is web‑based, requiring an attacker to host a malicious site that loads the vulnerable application in an iframe. If the victim interacts with the iframe, the attacker could potentially phish, perform CSRF, or leak data, but actual exploitation is considered unlikely under current conditions.
OpenCVE Enrichment