Impact
HCL Software iControl contains an insecure Cross-Origin Resource Sharing (CORS) policy that permits a malicious website to send requests with credentials. An attacker could exploit this flaw to read data from the victim’s session and exfiltrate sensitive information. The weakness is an improper authorization control that allows cross‑origin credentialed access to protected resources, which could compromise confidentiality of data accessed by the victim’s authenticated session.
Affected Systems
The affected vendor is HCL Software, product iControl. No specific versions are listed in the available data, so all current installations of iControl should be considered potentially vulnerable until a vendor update is released.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector is inferred to be web‑based: a user must be logged in to iControl and visit a malicious site that can choose any origin allowed by the flawed CORS policy. The vulnerability allows data disclosure but does not provide privileged code execution or system compromise.
OpenCVE Enrichment