Impact
This vulnerability allows an attacker to cause sensitive data to be inadvertently exposed by including it in URL parameters. The data may appear in the browser history, server logs, or be transmitted through intermediary devices, potentially leading to unauthorized disclosure under certain conditions. The weakness originates from improper handling of query string data, identified as CWE-598.
Affected Systems
The CNA indicates that HCL AION is affected. No specific product versions are listed, implying that all deployments may be susceptible until a vendor fix is available.
Risk and Exploitability
The CVSS score of 2.6 classifies the issue as low severity; the EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog. Attack vectors would involve the delivery of crafted URLs or exploitation of existing URL inputs. Because the flaw only exposes data already present in the application, it does not grant code execution or privilege escalation, but it can lead to privacy or compliance violations if sensitive information is logged or cached.
OpenCVE Enrichment