4 vulnerabilities classified as CWE-1032 (OWASP 2017年十大分类A6-安全配置错误). AI Chinese analysis included.
This page aggregates vulnerability data related to the Common Weakness Enumeration identifier CWE-1032, known as "Softcoded Web Password." It serves as a centralized resource for analyzing security flaws associated with this specific weakness type across various software vendors and products. The content collected on this page spans multiple years of reported security incidents, focusing on vulnerabilities where developers or administrators have hardcoded credentials into web application source code rather than using secure configuration management or external secret storage solutions. Readers can utilize this resource to track vendor advisories for affected software, understand the broader implications of the CWE-1032 weakness class within the software development lifecycle, and examine the historical vulnerability records of specific products that suffer from this configuration error. This aggregation provides insight into how frequently this misconfiguration occurs and which sectors are most heavily impacted. By reviewing the compiled data, security professionals can better identify patterns in softcoded password implementations and assess the risk exposure of their own environments. The page emphasizes the importance of distinguishing between hardcoded secrets and properly managed credentials, highlighting the persistent nature of this vulnerability despite widespread awareness. This structured overview aids in both reactive incident response and proactive remediation strategies by offering a clear view of the threat landscape surrounding weak credential management in web applications. The data reflects real-world exploitation scenarios and vendor disclosure timelines, providing context for risk assessment efforts.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-52629 | HCL AION is susceptible to Missing Content-Security-Policy — AION | 3.7 | Low | 2026-02-03 |
| CVE-2025-52624 | HCL AION is susceptible to Bypass of the script allow list configuration vulnerability — AION | 5.4 | Medium | 2025-10-10 |
| CVE-2025-52635 | HCL AION is susceptible to Trusted types in scripts not enforced in CSP — AION | 3.7 | Low | 2025-10-10 |
| CVE-2025-52650 | HCL AION is susceptible to Inline script execution allowed in CSP vulnerability — HCL AION | 8.2 | High | 2025-10-10 |
Vulnerabilities classified as CWE-1032 (OWASP 2017年十大分类A6-安全配置错误) represent 4 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.