Lucy Mobile App Vulnerable to CORS Misconfiguration
CVE-2023-37526
6.5MEDIUM
Key Information
- Vendor
- Hcl Software
- Status
- Dryice Lucy
- Vendor
- CVE Published:
- 14 May 2024
Summary
HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning attacks.
Affected Version(s)
DRYiCE Lucy = v9
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database