← back
CVE-2025-52628mediumCWE-1275

HCL AION is susceptible to Missing SameSite vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.6epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
In short

HCL AION 2.0 doesn't properly protect cookies from being sent in cross-site requests, which can allow attackers to trick users into performing unwanted actions on their accounts.

Technical detail

The application fails to set the SameSite attribute on cookies, allowing them to be transmitted in cross-site requests. This enables Cross-Site Request Forgery (CSRF) attacks where an attacker can forge requests on behalf of authenticated users. The vulnerability affects AION 2.0 and requires user interaction through a malicious third-party site.

Summary generated and translated by AI from the official description.
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Affected products
HCL · AION