HCL Aftermarket DPC is affected by Improper Input Validation
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.5epss 1.0%
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
nono source reports it
In short
HCL Aftermarket DPC doesn't properly check user input, allowing attackers to inject harmful code that could execute commands or steal data through techniques like XSS and SQL Injection.
Technical detail
The application fails to validate and sanitize user-supplied input before processing it, enabling code injection attacks including XSS, SQL Injection, and Command Injection depending on how the input is used in the application context.
Summary generated and translated by AI from the official description.
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Affected products
HCL · Aftermarket DPC