HCL Aftermarket DPC is affected by SQL Injection
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
In short
HCL Aftermarket DPC contains a SQL Injection flaw that lets attackers run unauthorized database commands to steal sensitive data. This happens when user input isn't properly filtered before being used in database queries.
Technical detail
SQL Injection vulnerability in HCL Aftermarket DPC allows unauthenticated or low-privileged attackers to inject malicious SQL statements into input parameters, bypassing input validation. This enables unauthorized database access, data extraction, and potential privilege escalation or system compromise depending on database permissions.
Summary generated and translated by AI from the official description.
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H
Affected products
HCL · Aftermarket DPC