5.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
Description
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
Basic Information
ID
CVE-2025-55266
Source
HCL
Published
Mar 26, 2026 at 13:02
Modified
Mar 26, 2026 at 15:01
Affected Product
Vendor
HCL
Product
Aftermarket DPC
Version
version 1.0.0
Affected Versions
HCL Aftermarket DPC version 1.0.0