Impact
HCL AION permits data to be embedded in JavaScript responses that can be referenced by pages hosted outside the original domain, allowing an attacker-controlled site to capture that data. The weakness is identified as a form of cross-site request forgery enabled by improper origin checks (CWE-352). The resulting exploit can lead to unauthorized disclosure of sensitive information woven into client‑side scripts.
Affected Systems
The affected product is HCL Software AION. No specific version information is provided, so all installations of the application remain potentially vulnerable until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 3.7 indicates limited impact compared to high‑severity flaws. With no EPSS data and the vulnerability not listed in CISA KEV, the likelihood of widespread exploitation appears low but non‑negligible. Attackers would likely need to host a malicious page that can reference the vulnerable JavaScript response, implying a cross‑origin dependency that may be mitigated by restricting same‑origin policies.
OpenCVE Enrichment