HCL Aftermarket DPC是印度HCL公司的一个数字化备件与售后服务管理平台。 HCL Aftermarket DPC存在安全漏洞,该漏洞源于跨域资源共享配置不当,可能导致敏感用户信息泄露、API未经授权访问以及数据篡改或泄露,攻击者可利用此配置不当窃取敏感数据或以合法用户身份执行操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL | Aftermarket DPC | version 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-55262 | 8.3 HIGH | HCL Aftermarket DPC is affected by SQL Injection |
| CVE-2025-55261 | 8.1 HIGH | HCL Aftermarket DPC is affected by Missing Functional Level Access Control |
| CVE-2025-55263 | 7.3 HIGH | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data |
| CVE-2025-55265 | 6.5 MEDIUM | HCL Aftermarket DPC is affected by File Discovery |
| CVE-2025-55266 | 5.9 MEDIUM | HCL Aftermarket DPC is affected by Session Fixation |
| CVE-2025-55267 | 5.7 MEDIUM | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability |
| CVE-2025-55264 | 5.5 MEDIUM | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change |
| CVE-2025-55273 | 4.3 MEDIUM | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability |
| CVE-2025-55268 | 4.3 MEDIUM | HCL Aftermarket DPC is affected by Spamming Vulnerability |
| CVE-2025-55269 | 4.2 MEDIUM | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability |
| CVE-2025-55275 | 3.7 LOW | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability |
| CVE-2025-55270 | 3.5 LOW | HCL Aftermarket DPC is affected by Improper Input Validation |
| CVE-2025-55272 | 3.1 LOW | HCL Aftermarket DPC is affected by Banner Disclosure vulnerability |
| CVE-2025-55276 | 3.1 LOW | HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability |
| CVE-2025-55271 | 3.1 LOW | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability |
| CVE-2025-55277 | 2.6 LOW | HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability |
No comments yet