← back
CVE-2025-55267mediumCWE-434

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.7epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
In short

HCL Aftermarket DPC allows attackers to upload harmful files without proper checks, which can then be executed to take complete control of the server.

Technical detail

An unrestricted file upload vulnerability (CWE-434) in HCL Aftermarket DPC permits unauthenticated or authenticated attackers to upload arbitrary files to the server. If uploaded files are executable or interpreted by the server, this leads to remote code execution and full server compromise.

Summary generated and translated by AI from the official description.
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Affected products
HCL · Aftermarket DPC